Out-of-bounds read - CVE-2019-12790
Published: June 10, 2019 / Updated: August 4, 2020
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This. A remote attacker can perform a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c.
How to mitigate CVE-2019-12790
Sources
- https://github.com/radare/radare2/issues/14211
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IEXZWAMVKGZKHALV4IVWQS2ORJKRH57U/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SX4TLTE75VYUGSPYEKMYFPUZMRDIR7O2/