CVE-2019-12829: Buffer Overflow
radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm/asm.c and libr/parse/parse.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12829?
CVE-2019-12829 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2019-12829?
To fix CVE-2019-12829, update your radare2 installation to a version beyond 3.5.1.
What components are affected by CVE-2019-12829?
CVE-2019-12829 affects the libr/asm/asm.c and libr/parse/parse.c files within radare2.
What type of attack does CVE-2019-12829 facilitate?
CVE-2019-12829 allows remote attackers to potentially crash the application or cause other unspecified impacts.
What versions of radare2 are vulnerable to CVE-2019-12829?
Radare2 versions up to and including 3.5.1 are vulnerable to CVE-2019-12829.