First published: Tue Aug 11 2020(Updated: )
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Radare Radare2 | =4.5.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17487 is a vulnerability in radare2 4.5.0 that misparses signature information in PE files causing a segmentation fault.
CVE-2020-17487 has a severity value of 7.5, classified as high.
CVE-2020-17487 in radare2 4.5.0 is caused by a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
CVE-2020-17487 can be exploited by misparsing signature information in PE files, leading to a segmentation fault.
At the moment, there are patches and updates available to address CVE-2020-17487 in radare2 4.5.0.