4.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): LOW
by @jopejoe1 Activity log
- Created automatic suggestion
-
@jopejoe1
removed
2 packages
- rizinPlugins.sigdb
- cutterPlugins.sigdb
- @jopejoe1 accepted
- @jopejoe1 removed maintainer @chayleaf
- @jopejoe1 published on GitHub
Rizin has a heap overflow on mach0_chained_fixups.c
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.
References
- https://github.com/rizinorg/rizin/security/advisories/GHSA-f3v7-xhmj-9cjj x_refsource_CONFIRM
- https://github.com/rizinorg/rizin/issues/5768 x_refsource_MISC
- https://github.com/rizinorg/rizin/pull/5770 x_refsource_MISC
- https://github.com/rizinorg/rizin/commit/41ea75d5b07d9b41b27ae80675cdda65f1b1c989 x_refsource_MISC
- https://github.com/rizinorg/rizin/blob/6dd0dba9ff4dc706f549d0cdcd93856b49e59aa0/librz/bin/format/mach0/mach0_chained_fixups.c#L200 x_refsource_MISC
- https://github.com/rizinorg/rizin/releases/tag/v0.8.2 x_refsource_MISC
- https://github.com/rizinorg/rizin/blob/6dd0dba9ff4dc706f549d0cdcd93856b49e59aa0/librz/bin/format/mach0/mach0_chained_fixups.c#L200 x_refsource_MISC
- https://github.com/rizinorg/rizin/releases/tag/v0.8.2 x_refsource_MISC
- https://github.com/rizinorg/rizin/security/advisories/GHSA-f3v7-xhmj-9cjj x_refsource_CONFIRM
- https://github.com/rizinorg/rizin/issues/5768 x_refsource_MISC
- https://github.com/rizinorg/rizin/pull/5770 x_refsource_MISC
- https://github.com/rizinorg/rizin/commit/41ea75d5b07d9b41b27ae80675cdda65f1b1c989 x_refsource_MISC
Affected products
- ==< 0.8.2
Package maintainers
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@makefu Felix Richter <makefu@syntax-fehler.de>
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>