CVE-2022-1240

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/04/2022
Last modified:
14/04/2022

Description

Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* 5.6.6 (including)