CVE-2017-6387: Medium severity Radare Radare2 vulnerability
Published Mar 2, 2017
·Updated
The dexloadcode function in libr/bin/p/bindex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
Affected Software
1 affected component
Radare Radare2=1.2.1
Remediation
Patch Available
Event History
Mar 2, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6387?
CVE-2017-6387 has a severity rating that indicates it can lead to denial of service due to an out-of-bounds read.
2
How do I fix CVE-2017-6387?
To fix CVE-2017-6387, update radare2 to a version that has addressed this vulnerability.
3
What type of attack does CVE-2017-6387 facilitate?
CVE-2017-6387 facilitates a denial of service attack through the processing of a malicious DEX file.
4
Which versions of radare2 are affected by CVE-2017-6387?
CVE-2017-6387 specifically affects radare2 version 1.2.1.
5
What component of radare2 is impacted by CVE-2017-6387?
The dex_loadcode function in libr/bin/p/bin_dex.c is the component impacted by CVE-2017-6387.