漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow
Vulnerability Description
A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. The exploit is publicly available and might be used. The name of the patch is 84e773986e7e5bb30453a9384f498ec0ccc9d0a9. A patch should be applied to remediate this issue.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
Radare2 数字错误漏洞
Vulnerability Description
Radare Radare2是Radare团队开源的一个面向 Unix 极客的 Libre 反向框架。 Radare2存在数字错误漏洞,该漏洞源于文件libr/core/cmd_anal.inc.c中的cmd_anal_opcode函数在hexpairs Parser组件中存在整数溢出问题。以下版本受到影响:6.1.0版本、6.1.1版本、6.1.2版本、6.1.3版本、6.1.4版本、6.1.5版本和6.1.6版本。
CVSS Information
N/A
Vulnerability Type
N/A