First published: Tue Aug 22 2023(Updated: )
A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Radare Radare2 | =5.4.0 | |
Radare Radare2 | =5.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28068 is a vulnerability in the r_sleb128 function in radare2 5.4.2 and 5.4.0, which allows a heap buffer overflow.
CVE-2022-28068 has a severity level of high (7.5).
Radare2 versions 5.4.0 and 5.4.2 are affected by CVE-2022-28068.
To fix CVE-2022-28068, it is recommended to update to a version of radare2 that is not affected, such as a version after 5.4.2.
You can find more information about CVE-2022-28068 at the following link: [GitHub - radareorg/radare2 commit](https://github.com/radareorg/radare2/commit/637f4bd1af6752e28e0a9998e954e2e9ce6fa992)