CVE-2017-9949: High severity radare2 vulnerability
The grubmemmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9949?
CVE-2017-9949 is considered a medium severity vulnerability due to its potential for denial of service and application crashes.
How do I fix CVE-2017-9949?
To fix CVE-2017-9949, upgrade to a patched version of radare2 that addresses the buffer underflow issue.
What type of attack does CVE-2017-9949 allow?
CVE-2017-9949 allows remote attackers to cause a denial of service and potentially other unspecified impacts through crafted binary files.
Which version of radare2 is affected by CVE-2017-9949?
CVE-2017-9949 affects radare2 version 1.5.0.
What is the main impact of CVE-2017-9949 on applications?
The main impact of CVE-2017-9949 is a stack-based buffer underflow leading to application crashes.