First published: Thu Jun 08 2017(Updated: )
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
radare2 | =1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9520 is a high-severity vulnerability that can lead to denial of service through a use-after-free condition.
To fix CVE-2017-9520, update radare2 to a version beyond 1.5.0 that includes the patch addressing this vulnerability.
CVE-2017-9520 allows remote attackers to exploit the vulnerability through crafted DEX files, causing crashes.
CVE-2017-9520 exists in radare2 version 1.5.0.
While CVE-2017-9520 primarily results in application crashes, it may lead to potential data loss depending on the state of the application at the time of the crash.