CVE Database
/

CVE-2019-14745

Back to search

CVE-2019-14745

Published: Aug 7, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2019-e931422a81
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-b3de19c346
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-65c33bdc2a
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now