CVE-2019-16718
Summary
| CVE | CVE-2019-16718 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-23 14:15:00 UTC |
| Updated | 2020-11-16 19:21:00 UTC |
| Description | In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to an insufficient fix for CVE-2019-14745 and improper handling of symbol names embedded in executables. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Comparing 3.8.0...3.9.0 · radareorg/radare2 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Fix #14990 - multiple quoted command parsing issue ##core · radareorg/radare2@dd739f5 · GitHub | MISC | github.com | Third Party Advisory |
| More fixes for the CVE-2019-14745 · radareorg/radare2@5411543 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.