CVE-2025-1788
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
01/03/2025
Last modified:
03/03/2025
Description
A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz_utf8_encode in the library /librz/util/utf8.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/rizinorg/rizin/issues/4910
- https://github.com/rizinorg/rizin/issues/4910#issuecomment-2662963253
- https://github.com/rizinorg/rizin/pull/4762
- https://github.com/user-attachments/files/18817099/rz-bin-poc-01.zip
- https://vuldb.com/?ctiid_298011=
- https://vuldb.com/?id_298011=
- https://vuldb.com/?submit_502345=
- https://github.com/rizinorg/rizin/issues/4910#issuecomment-2662963253