CVE-2022-28068: Buffer Overflow
Published Aug 22, 2023
·Updated
A heap buffer overflow in rsleb128 function in radare2 5.4.2 and 5.4.0.
Affected Software
2 affected components
Radare Radare2=5.4.0
Radare Radare2=5.4.2
Remediation
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-28068?
CVE-2022-28068 is a vulnerability in the r_sleb128 function in radare2 5.4.2 and 5.4.0, which allows a heap buffer overflow.
2
What is the severity of CVE-2022-28068?
CVE-2022-28068 has a severity level of high (7.5).
3
Which software versions are affected by CVE-2022-28068?
Radare2 versions 5.4.0 and 5.4.2 are affected by CVE-2022-28068.
4
How can I fix CVE-2022-28068?
To fix CVE-2022-28068, it is recommended to update to a version of radare2 that is not affected, such as a version after 5.4.2.
5
Where can I find more information about CVE-2022-28068?
You can find more information about CVE-2022-28068 at the following link: [GitHub - radareorg/radare2 commit](https://github.com/radareorg/radare2/commit/637f4bd1af6752e28e0a9998e954e2e9ce6fa992)