CVE-2020-16269: Medium severity radare2 vulnerability
Published Aug 3, 2020
·Updated
radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parsetypedef in typedwarf.c via a malformed DWATname in the .debuginfo section.
Affected Software
3 affected components
Radare Radare2=4.5.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Remediation
Patch Available
Event History
Aug 3, 2020
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-16269?
CVE-2020-16269 is classified as a medium severity vulnerability due to its potential to cause a segmentation fault.
2
How do I fix CVE-2020-16269?
To fix CVE-2020-16269, upgrade to the latest version of radare2 that addresses this vulnerability.
3
Which versions of radare2 are affected by CVE-2020-16269?
CVE-2020-16269 affects radare2 version 4.5.0.
4
On which operating systems is CVE-2020-16269 applicable?
CVE-2020-16269 is applicable on Fedora versions 32 and 33 that have radare2 4.5.0 installed.
5
What causes the CVE-2020-16269 vulnerability?
CVE-2020-16269 is caused by improper parsing of malformed DW_AT_name attributes in the .debug_info section of executable files.