REDHAT-BUG-2329102: Command Injection
The vulnerability in Radare2 affects versions up to and including 5.9.8. When processing malicious Pebble Application files, Radare2 improperly sanitizes user-controlled input, leading to command injection. This allows arbitrary shell commands to execute during file handling. The issue was confirmed in version 5.9.7 on Linux x86-64 and demonstrated with a Base64-encoded test file
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2329102?
The severity of REDHAT-BUG-2329102 is considered high due to the potential for command injection.
How do I fix REDHAT-BUG-2329102?
To fix REDHAT-BUG-2329102, update Radare2 to a version newer than 5.9.8 to ensure proper input sanitization.
What versions of Radare2 are affected by REDHAT-BUG-2329102?
Radare2 versions up to and including 5.9.8 are affected by REDHAT-BUG-2329102.
What type of vulnerability is REDHAT-BUG-2329102?
REDHAT-BUG-2329102 is classified as a command injection vulnerability.
Can REDHAT-BUG-2329102 allow unauthorized access to my system?
Yes, REDHAT-BUG-2329102 can potentially allow arbitrary shell commands to execute, leading to unauthorized access.