First published: Wed Apr 06 2022(Updated: )
Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Radare Radare2 | <5.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1237 is a vulnerability in the GitHub repository radareorg/radare2 that allows for heap overflow and potential exploitation.
CVE-2022-1237 has a severity rating of 7.8 (high).
CVE-2022-1237 affects Radare Radare2 versions up to, but not including, 5.6.8.
To fix CVE-2022-1237, it is recommended to update Radare Radare2 to version 5.6.8 or later.
You can find more information about CVE-2022-1237 on the GitHub page (https://github.com/radareorg/radare2/commit/2d782cdaa2112c10b8dd5e7a93c134b2ada9c1a6) and the Huntr.dev page (https://huntr.dev/bounties/ad3c9c4c-76e7-40c8-bd4a-c095acd8bb40).