Intel

AIKIDO-2024-10456

radareorg.radare2 is vulnerable to Code Injection

Code Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 20, 2024

90

Critical Risk

This Affects:

c++radareorg.radare2
2.1.0 - 5.9.7
Fixed in 5.9.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to code injection, allowing arbitrary shell commands to be embedded in a Pebble Application file. When such a file is opened, the commands execute before reaching the r2 shell prompt. This critical vulnerability can lead to Remote Code Execution (RCE) or Denial of Service (DoS).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

radareorg.radare2 is vulnerable to Code Injection in versions 2.1.0 - 5.9.7.

How to fix this

Upgrade the radareorg.radare2 library to the patch version.