CVE-2020-17487: High severity radare2 vulnerability
Published Aug 11, 2020
·Updated
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in rx509parsealgorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGEDIRECTORYENTRYSECURITY.
Affected Software
3 affected components
Radare Radare2=4.5.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Aug 11, 2020
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description
Frequently Asked Questions
1
What is CVE-2020-17487?
CVE-2020-17487 is a vulnerability in radare2 4.5.0 that misparses signature information in PE files causing a segmentation fault.
2
How severe is CVE-2020-17487?
CVE-2020-17487 has a severity value of 7.5, classified as high.
3
What causes CVE-2020-17487 in radare2 4.5.0?
CVE-2020-17487 in radare2 4.5.0 is caused by a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
4
How can CVE-2020-17487 be exploited?
CVE-2020-17487 can be exploited by misparsing signature information in PE files, leading to a segmentation fault.
5
Is there a fix available for CVE-2020-17487?
At the moment, there are patches and updates available to address CVE-2020-17487 in radare2 4.5.0.