CVE-2017-7716: Medium severity Radare Radare2 vulnerability
Published Apr 12, 2017
·Updated
The readu32leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.
Affected Software
1 affected component
Radare Radare2=1.3.0
Remediation
Patch Available
Event History
Apr 12, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7716?
CVE-2017-7716 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-7716?
To fix CVE-2017-7716, upgrade to a version of radare2 later than 1.3.0.
3
What type of attack does CVE-2017-7716 facilitate?
CVE-2017-7716 allows remote attackers to cause a denial of service through a crafted Web Assembly file.
4
Which versions of radare2 are affected by CVE-2017-7716?
CVE-2017-7716 specifically affects radare2 version 1.3.0.
5
What is the impact of CVE-2017-7716?
The impact of CVE-2017-7716 is a heap-based buffer over-read that can lead to an application crash.