#VU74033 Stack-based buffer overflow in Rizin - CVE-2023-27590
Published: March 27, 2023
Rizin
Rizin
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling GDB registers files. A remote attacker can trick the victim to open a specially crafted GDB registers file, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://github.com/rizinorg/rizin/security/advisories/GHSA-rqcp-m8m2-jcqf
- https://github.com/rizinorg/rizin/pull/3422
- https://github.com/rizinorg/rizin/commit/d6196703d89c84467b600ba2692534579dc25ed4
- https://github.com/rizinorg/rizin/blob/3a7d5116244beb678ad9950bb9dd27d28ed2691f/librz/reg/profile.c#L545
- https://github.com/rizinorg/rizin/blob/3a7d5116244beb678ad9950bb9dd27d28ed2691f/librz/reg/profile.c#L514
- https://github.com/rizinorg/rizin/releases/tag/v0.5.2