CVE-2018-20456: Medium severity radare2 vulnerability
Published Dec 25, 2018
·Updated
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asmx86nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.
Affected Software
1 affected component
Radare Radare2<3.1.1
Remediation
Event History
Dec 25, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20456?
CVE-2018-20456 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2018-20456?
To mitigate CVE-2018-20456, upgrade to radare2 version 3.1.1 or later.
3
What attack vector can exploit CVE-2018-20456?
CVE-2018-20456 can be exploited by providing a specially crafted input file to radare2.
4
What component of radare2 is affected by CVE-2018-20456?
The vulnerability in CVE-2018-20456 affects the parseOperand function in libr/asm/p/asm_x86_nz.c.
5
What are the potential consequences of CVE-2018-20456?
Exploitation of CVE-2018-20456 may lead to an application crash due to a stack-based buffer over-read.