CVE-2019-19647: Null Pointer Dereference
radare2 through 4.0.0 lacks validation of the content variable in the function rasmpseudoincbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19647?
The severity of CVE-2019-19647 is classified as high due to the potential for arbitrary write operations and denial of service.
How do I fix CVE-2019-19647?
To fix CVE-2019-19647, upgrade radare2 to version 4.0.1 or later, or apply available patches provided by the software maintainers.
Which versions of radare2 are affected by CVE-2019-19647?
CVE-2019-19647 affects radare2 versions up to and including 4.0.0.
Can CVE-2019-19647 lead to remote attacks?
Yes, CVE-2019-19647 allows remote attackers to exploit the vulnerability via crafted input, potentially causing application crashes.
What type of vulnerability is CVE-2019-19647?
CVE-2019-19647 is classified as an arbitrary write vulnerability due to insufficient validation in the affected software.