Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.
The product does not adequately filter user-controlled input for special elements with control implications.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Link | Tags |
---|---|
https://huntr.dev/bounties/583133af-7ae6-4a21-beef-a4b0182cf82e | patch exploit third party advisory issue tracking |
https://github.com/radareorg/radare2/commit/961f0e723903011d4f54c2396e44efa91fcc74ce | third party advisory patch |