radareorg.radare2 is vulnerable to Out-of-bounds Read
33
Low Risk
Affected versions of this package contain a heap out-of-bounds read in r_bin_java_line_number_table_attr_new in the Java class parser. A short LineNumberTable attribute can pass a size check and then be read past the allocated buffer. Opening a malformed Java .class file can crash radareorg.radare2. The patch tightens the minimum size check before the attribute is parsed.
You are affected if you are using a version that falls within the vulnerable range and open or analyze an untrusted Java .class file with radare2 or rabin2.
radareorg.radare2 is vulnerable to Out-of-bounds Read in versions 0.9.6 - 6.1.6.
Upgrade the radareorg.radare2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant