CVE-2022-1240: Heap buffer overflow in libr/bin/format/mach0/mach0.c in radareorg/radare2
Published Apr 6, 2022
·Updated
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the rstrncpy function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see CWE.
Affected Software
1 affected component
Radare Radare2<=5.6.6
Remediation
Event History
Apr 6, 2022
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1240.
2
What is the severity of CVE-2022-1240?
The severity of CVE-2022-1240 is high (7.8).
3
Which software is affected by CVE-2022-1240?
The software affected by CVE-2022-1240 is Radare Radare2 version up to 5.6.6.
4
What can happen if address sanitizer is disabled in the compiling process?
If address sanitizer is disabled during the compiling process, a heap buffer overflow can occur.
5
Is CVE-2022-1240 likely to be exploitable?
Yes, CVE-2022-1240 is likely to be exploitable.