A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://cwe.mitre.org/data/definitions/122.html | technical description |
https://github.com/radareorg/radare2-extras/pull/255 | third party advisory patch |
https://github.com/radareorg/radare2-extras/pull/255/commits/4a8b24475549ff10bdf6d07fd4b5f6c1cc6246ea | third party advisory patch |
https://github.com/radareorg/radare2-extras/pull/255/commits/9f6a221433964d9b14f3ed78bc9fb059395b893b | third party advisory patch |