Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2020-0100 Moderate: radare2 Integer Overflow Exploits

mageia
Calendar Grey February 24, 2020
Dist Mageia Esm H88
Mageia's latest radare2 enhancement addresses urgent security concerns, including denial of service threats and potential remote execution weaknesses.
Updated radare2 packages fix security vulnerabilities: A vulnerability was found in radare2 through 4.0, there is an integer overflow for the variable new_token_size in the functi...

Summary

Updated radare2 packages fix security vulnerabilities:
A vulnerability was found in radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free. This allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted input (CVE-2019-19590).
radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input (CVE-2019-19647).
The radare2 package has been updated to version 4.2.1, fixing these issues and other bugs.
Also, the radare2-cutter package has been updated to version 1.10.1.

References

- https://bugs.mageia.org/show_bug.cgi?id=26232

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DUW4XXPI6XCI2G4X22EP3TKU2APLQ5XD/

- https://www.cve.org/CVERecord?id=CVE-2019-19590

- https://www.cve.org/CVERecord?id=CVE-2019-19647

Resolution

SRPMS

- 7/core/radare2-4.2.1-1.mga7

- 7/core/radare2-cutter-1.10.1-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 24 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0100.html
Type: security
CVE: CVE-2019-19590, CVE-2019-19647

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here