Vulnerability Description
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Radare | Radare2-Extras | < 5.1.0 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/122.htmlTechnical Description
- https://github.com/radareorg/radare2-extras/pull/255PatchThird Party Advisory
- https://github.com/radareorg/radare2-extras/pull/255/commits/4a8b24475549ff10bdfPatchThird Party Advisory
- https://github.com/radareorg/radare2-extras/pull/255/commits/9f6a221433964d9b14fPatchThird Party Advisory
- https://cwe.mitre.org/data/definitions/122.htmlTechnical Description
- https://github.com/radareorg/radare2-extras/pull/255PatchThird Party Advisory
- https://github.com/radareorg/radare2-extras/pull/255/commits/4a8b24475549ff10bdfPatchThird Party Advisory
- https://github.com/radareorg/radare2-extras/pull/255/commits/9f6a221433964d9b14fPatchThird Party Advisory
FAQ
What is CVE-2020-24133?
CVE-2020-24133 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
How severe is CVE-2020-24133?
CVE-2020-24133 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24133?
Check the references section above for vendor advisories and patch information. Affected products include: Radare Radare2-Extras.