CVE-2021-3673: Input Validation
Published Aug 2, 2021
·Updated
A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
Affected Software
4 affected components
Radare Radare2=5.3.1
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
radareorg/radare2to a version that resolves this vulnerability.Fixed in 5.3.1Patch d7ea20fb2e1433ebece9f004d87ad8f2377af23d
Event History
Aug 2, 2021
Data Sourced
via Red Hat·01:56 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-3673.
2
What is the severity of CVE-2021-3673?
The severity of CVE-2021-3673 is high with a CVSS score of 7.5.
3
How does CVE-2021-3673 affect Radare2?
CVE-2021-3673 affects Radare2 version 5.3.1.
4
What is the impact of CVE-2021-3673?
CVE-2021-3673 can lead to resource exhaustion and DoS.
5
How can I fix CVE-2021-3673?
To fix CVE-2021-3673, update to a patched version of Radare2 (version 5.3.2 or later).