CVE-2018-12320: Use After Free
Published Jun 13, 2018
·Updated
There is a use after free in radare2 2.6.0 in ranalbbfree() in libr/anal/bb.c via a crafted Java binary file.
Affected Software
1 affected component
Radare Radare2=2.6.0
Remediation
Event History
Jun 13, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12320?
CVE-2018-12320 is rated as a high-severity vulnerability due to its potential for exploitation in crafted Java binary files.
2
How do I fix CVE-2018-12320?
To fix CVE-2018-12320, upgrade radare2 to version 2.6.1 or later where the vulnerability is addressed.
3
What is the impact of CVE-2018-12320?
CVE-2018-12320 can lead to memory corruption issues that may be exploited by attackers to execute arbitrary code.
4
Which version of radare2 is affected by CVE-2018-12320?
CVE-2018-12320 affects radare2 version 2.6.0.
5
Is CVE-2018-12320 a local or remote vulnerability?
CVE-2018-12320 is considered a local vulnerability as it requires an attacker to have access to the affected system to exploit it.