CVE-2022-34520: Null Pointer Dereference
Published Jul 22, 2022
·Updated
Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function rbinfilextrloadbuffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.
Affected Software
1 affected component
Radare Radare2=5.7.2
Event History
Jul 22, 2022
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-34520.
2
What is the affected software?
The affected software is Radare2 version 5.7.2.
3
What is the severity of CVE-2022-34520?
The severity of CVE-2022-34520 is medium with a severity value of 5.5.
4
What is the description of CVE-2022-34520?
CVE-2022-34520 is a vulnerability in Radare2 version 5.7.2 that allows attackers to cause a Denial of Service (DOS) via a crafted binary file.
5
How can I fix CVE-2022-34520?
To fix CVE-2022-34520, update Radare2 to a version that does not contain this vulnerability.