CVE-2022-1649

Name
CVE-2022-1649
Description
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/radareorg/radare2/commit/a5aafb99c3965259c84ddcf45a91144bf7eb4cf1
CONFIRM https://huntr.dev/bounties/c07e4918-cf86-4d2e-8969-5fb63575b449

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* radare2 >= None < 5.7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
radare2 3.15-community 5.5.0-r0 Valery Kartel <valery.kartel@gmail.com> possibly vulnerable
radare2 3.16-community 5.6.8-r0 Valery Kartel <valery.kartel@gmail.com> possibly vulnerable