First published: Mon Apr 03 2017(Updated: )
The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
radare2 | =1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6448 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2017-6448, upgrade radare2 to version 1.3.0 or later, as this version addresses the vulnerability.
CVE-2017-6448 affects radare2 version 1.2.1 specifically, allowing remote attackers to exploit it.
CVE-2017-6448 is a stack-based buffer overflow vulnerability leading to application crashes or denial of service.
CVE-2017-6448 does not explicitly allow remote code execution but may lead to unspecified impacts including service disruptions.