CVE-2018-12321: High severity radare2 vulnerability
Published Jun 13, 2018
·Updated
There is a heap out of bounds read in radare2 2.6.0 in javaswitchop() in libr/anal/p/analjava.c via a crafted Java binary file.
Affected Software
1 affected component
Radare Radare2=2.6.0
Remediation
Event History
Jun 13, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12321?
The severity of CVE-2018-12321 is classified as high due to the potential exploitation of a heap out of bounds read.
2
How do I fix CVE-2018-12321?
To fix CVE-2018-12321, upgrade to a version of radare2 that is newer than 2.6.0.
3
What is the impact of CVE-2018-12321?
The impact of CVE-2018-12321 includes potential denial of service and information disclosure when handling crafted Java binary files.
4
Who is affected by CVE-2018-12321?
Users of radare2 version 2.6.0 are affected by CVE-2018-12321.
5
What components are involved in CVE-2018-12321?
CVE-2018-12321 involves the java_switch_op() function within libr/anal/p/anal_java.c in the radare2 software.