radareorg.radare2 is vulnerable to Out-of-bounds Read
33
Low Risk
Affected versions of this package contain a heap out-of-bounds read in the Mach-O Swift field-metadata parser. The parser computes an index by subtracting the metadata-section base from an externally controlled relative pointer without checking that the pointer is within range, producing a negative index. A crafted Swift Mach-O file causes a read just before the allocated buffer, leading to incorrect processing or a crash. The patch validates the pointer range and uses verified unsigned indices before accessing the buffer.
You are affected if you use an affected version of radare2 or rabin2 to analyze an untrusted Swift Mach-O file. Parsing crafted Swift type/class metadata triggers the out-of-bounds read locally; no network exposure is required.
radareorg.radare2 is vulnerable to Out-of-bounds Read in versions 5.7.0 - 6.1.8.
Upgrade the radareorg.radare2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant