CVE-2022-28072: Buffer Overflow
Published Aug 22, 2023
·Updated
A heap buffer overflow in rreadle32 function in radare25.4.2 and 5.4.0.
Affected Software
2 affected components
Radare Radare2=5.4.0
Radare Radare2=5.4.2
Remediation
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this heap buffer overflow in radare2?
The vulnerability ID is CVE-2022-28072.
2
What is the severity of CVE-2022-28072?
The severity of CVE-2022-28072 is high with a CVSS score of 7.5.
3
Which versions of radare2 are affected by CVE-2022-28072?
The versions 5.4.0 and 5.4.2 of radare2 are affected by CVE-2022-28072.
4
How does the vulnerability manifest?
The vulnerability manifests as a heap buffer overflow in the r_read_le32 function in radare2.
5
How can I fix CVE-2022-28072?
To fix CVE-2022-28072, it is recommended to update radare2 to a version that includes the fix, such as version 5.4.3 or newer.