Integer overflow in radare2 - CVE-2019-19590
Published: December 5, 2019 / Updated: January 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer overflow for the variable "new_token_size" in the "r_asm_massemble" function in "libr/asm/asm.c". A remote attacker can trigger integer overflow, which will result in a Use-After-Free for the buffer tokens and cause a denial of service (DoS) condition or possibly execute arbitrary code via crafted input.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
cutter-re
radare2
How to mitigate CVE-2019-19590
radare2 - addressed in versions 4.2.1-1.el7, 4.2.1-1.fc30, 4.2.1-1.fc30.2, 4.2.1-1.fc31, 4.2.1-1.fc31.2, 4.2.1-2.fc30, 4.2.1-2.fc31
External References
Related Security Bulletins
- Integer overflow in radare2
- Fedora 31 update for cutter-re, radare2
- Fedora 30 update for cutter-re, radare2
- Fedora EPEL 7 update for radare2
- Fedora 30 update for cutter-re, radare2
- Fedora 31 update for cutter-re, radare2
- Fedora 31 update for cutter-re, radare2
- Fedora 30 update for cutter-re, radare2