First published: Mon Apr 11 2022(Updated: )
Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Radare Radare2 | <5.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1297.
The severity of CVE-2022-1297 is critical, with a CVSS score of 9.1.
The vulnerability affects Radare Radare2 versions prior to 5.6.8.
The vulnerability may allow attackers to read sensitive information or cause a crash.
To fix CVE-2022-1297, update Radare Radare2 to version 5.6.8 or newer.