CVE-2020-27794: Double Free
Published Aug 19, 2022
·Updated
A double free issue was discovered in radare2 in cmdinfo.c:cmdinfo(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
Affected Software
1 affected component
Radare Radare2<4.4.0
Remediation
Patch Available
Event History
Aug 19, 2022
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27794?
CVE-2020-27794 is a vulnerability in radare2 that allows for a double free issue, potentially leading to memory modification and crashes.
2
How can CVE-2020-27794 be exploited?
CVE-2020-27794 can be exploited by triggering the double free issue in radare2's cmd_info() function.
3
What is the severity of CVE-2020-27794?
CVE-2020-27794 has a severity rating of 9.1, which is considered critical.
4
Which version of radare2 is affected by CVE-2020-27794?
Radare2 versions up to and excluding 4.4.0 are affected by CVE-2020-27794.
5
Is there a fix available for CVE-2020-27794?
Yes, a fix for CVE-2020-27794 is available. It is recommended to update to a version of radare2 that is not affected by this vulnerability.