CVE-2023-47016

Name
CVE-2023-47016
Description
radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/radareorg/radare2/issues/22349
https://github.com/radareorg/radare2/commit/40c9f50e127be80b9d816bce2ab2ee790831aefd
https://gist.github.com/gandalf4a/65705be4f84269cb7cd725a1d4ab2ffa

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* radare2 >= None < 5.9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
radare2 edge-community 5.8.8-r1 Valery Kartel <valery.kartel@gmail.com> possibly vulnerable
radare2 3.18-community 5.8.6-r0 Valery Kartel <valery.kartel@gmail.com> possibly vulnerable
radare2 3.19-community 5.8.8-r1 Valery Kartel <valery.kartel@gmail.com> possibly vulnerable