CVE-2020-15121
Summary
| CVE | CVE-2020-15121 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-20 18:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Command injection during opening PE file with malformed debug symbol information (PDB) - `idpd` command · Advisory · radareorg/radare2 · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Command injection across r_sys_cmd* · Issue #16945 · radareorg/radare2 · GitHub |
MISC |
github.com |
Third Party Advisory |
| Fix command injection on PDB download (#16966) · radareorg/radare2@04edfa8 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Fix command injection on PDB download by GustavoLCR · Pull Request #16966 · radareorg/radare2 · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: cutter-re-1.11.0-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: cutter-re-1.11.0-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: radare2-4.5.0-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: radare2-4.5.0-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501234 Alpine Linux Security Update for radare2
- 505368 Alpine Linux Security Update for radare2