CVE-2017-7946: Use After Free
Published Apr 18, 2017
·Updated
The getrelocs64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.
Affected Software
1 affected component
Radare Radare2=1.3.0
Remediation
Patch Available
Event History
Apr 18, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7946?
CVE-2017-7946 is classified as a denial of service vulnerability due to a use-after-free issue.
2
How do I fix CVE-2017-7946?
To fix CVE-2017-7946, update radare2 to a version later than 1.3.0, as the issue has been addressed in subsequent releases.
3
What software is affected by CVE-2017-7946?
CVE-2017-7946 specifically affects radare2 version 1.3.0.
4
What impact does CVE-2017-7946 have on systems?
CVE-2017-7946 can lead to an application crash, causing a denial of service for users of the affected software.
5
Is CVE-2017-7946 an exploitable vulnerability?
CVE-2017-7946 can be exploited by remote attackers through crafted Mach0 files, making it a concern for users handling such files.