First published: Fri Aug 19 2022(Updated: )
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Radare Radare2 | <4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27794 is a vulnerability in radare2 that allows for a double free issue, potentially leading to memory modification and crashes.
CVE-2020-27794 can be exploited by triggering the double free issue in radare2's cmd_info() function.
CVE-2020-27794 has a severity rating of 9.1, which is considered critical.
Radare2 versions up to and excluding 4.4.0 are affected by CVE-2020-27794.
Yes, a fix for CVE-2020-27794 is available. It is recommended to update to a version of radare2 that is not affected by this vulnerability.