First published: Thu Mar 02 2017(Updated: )
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Radare2 | =1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6319 has a severity rating that indicates it can cause a denial of service through a buffer overflow.
To fix CVE-2017-6319, upgrade radare2 to a version that addresses this vulnerability, specifically above 1.2.1.
CVE-2017-6319 is classified as a buffer overflow vulnerability that can lead to application crashes.
CVE-2017-6319 specifically affects radare2 version 1.2.1.
Yes, CVE-2017-6319 can be exploited remotely through a crafted DEX file.