CVE-2019-12802: Use After Free
In radare2 through 3.5.1, the rcccontext function of libr/egg/egglang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in regglangparsechar; invalid free in rccpusharg).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12802?
CVE-2019-12802 has been classified as a denial of service vulnerability, which can lead to application crashes.
How do I fix CVE-2019-12802?
To fix CVE-2019-12802, update to radare2 version 3.5.2 or later.
What types of systems are affected by CVE-2019-12802?
CVE-2019-12802 affects radare2 versions up to and including 3.5.1 and specific versions of Fedora 29 and 30.
Can CVE-2019-12802 be exploited remotely?
Yes, CVE-2019-12802 can be exploited by remote attackers to cause denial of service.
What symptoms indicate an exploit of CVE-2019-12802?
Symptoms of an exploit may include application crashes or unexpected exits when processing certain contexts.