Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2019-19647

Published: 9 December 2019

radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input.

Priority

Medium

Cvss 3 Severity Score

7.8

Score breakdown

Status

Package Release Status
radare2
Launchpad, Ubuntu, Debian
focal Not vulnerable
(4.2.1+dfsg-1)
hirsute Does not exist

xenial Needed

bionic Needed

disco Ignored
(end of life)
eoan Ignored
(end of life)
groovy Not vulnerable
(4.2.1+dfsg-1)
impish Does not exist

jammy Does not exist

kinetic Does not exist

lunar Ignored
(end of life, was needs-triage)
trusty Does not exist

upstream
Released (4.1.0)
mantic Not vulnerable
(5.5.0+dfsg-1ubuntu1)
Patches:
upstream: https://github.com/radareorg/radare2/commit/07b5e062f2d4a00403ff031302cb18dfa58e3805

Severity score breakdown

Parameter Value
Base score 7.8
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H