Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed or circular LE fixup chains, relocation entries may be freed multiple times during error handling. A specially crafted LE binary can trigger heap corruption and cause the application to crash, resulting in a denial-of-service condition. An attacker with a crafted binary could cause a denial of service when the tool is integrated on a service pipeline.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Rizin 安全漏洞
Vulnerability Description
Rizin是Rizin组织的一个免费的开源逆向工程框架。用于分析二进制文件、反汇编代码、调试程序、作为取证工具、作为能够打开磁盘文件的可编写脚本的命令行十六进制编辑器等等。 Rizin存在安全漏洞,该漏洞源于le_load_fixup_record函数在处理畸形或循环LE修复链时,重定位条目可能在错误处理期间被多次释放,可能导致特制LE二进制文件触发堆损坏并导致应用程序崩溃,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A