CVE-2019-12790

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
10/06/2019
Last modified:
07/11/2023

Description

In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* 3.5.1 (including)