CVE-2022-1297: Out-of-bounds Read in r_bin_ne_get_entrypoints function in radareorg/radare2
Published Apr 11, 2022
·Updated
Out-of-bounds Read in rbinnegetentrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Affected Software
1 affected component
Radare Radare2<5.6.8
Remediation
Event History
Apr 11, 2022
CVE Published
via MITRE·11:50 AM
Data Sourced
via MITRE·11:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-1297.
2
What is the severity of CVE-2022-1297?
The severity of CVE-2022-1297 is critical, with a CVSS score of 9.1.
3
What is affected by CVE-2022-1297?
The vulnerability affects Radare Radare2 versions prior to 5.6.8.
4
What is the impact of CVE-2022-1297?
The vulnerability may allow attackers to read sensitive information or cause a crash.
5
How can CVE-2022-1297 be fixed?
To fix CVE-2022-1297, update Radare Radare2 to version 5.6.8 or newer.