CVE-2018-10187: Medium severity radare2 vulnerability
Published Apr 17, 2018
·Updated
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvikop function (libr/anal/p/analdalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier.
Affected Software
1 affected component
Radare Radare2=2.5.0
Event History
Apr 17, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10187?
CVE-2018-10187 is considered a critical severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2018-10187?
To fix CVE-2018-10187, upgrade radare2 to a version later than 2.5.0 that addresses this vulnerability.
3
What type of vulnerability is CVE-2018-10187?
CVE-2018-10187 is a heap-based buffer over-read vulnerability in the dalvik_op function.
4
Who is affected by CVE-2018-10187?
Users of radare2 version 2.5.0 are affected by CVE-2018-10187.
5
Can CVE-2018-10187 be exploited remotely?
Yes, CVE-2018-10187 can be exploited remotely by attackers through crafted DEX files.