Bug ID 1198804
Summary VUL-0: CVE-2022-1437: radare2: Heap-based Buffer Overflow
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/329922/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee stefan.bruens@rwth-aachen.de
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-1437

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to
5.7.0. The bug causes the program reads data past the end of the intented
buffer. Typically, this can allow attackers to read sensitive information from
other memory locations or cause a crash.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1437
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1437
https://github.com/radareorg/radare2/commit/669a404b6d98d5db409a5ebadae4e94b34ef5136
https://huntr.dev/bounties/af6c3e9e-b7df-4d80-b48f-77fdd17b4038


You are receiving this mail because: