← Back

CVE-2021-3674

nvd nist
Published: Mar 24, 2023Modified: Feb 25, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

Affected (1)

Products: Rizin: Rizin
1 product
Rizin
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.2.1

References (4)

Source: patrick@puiterwijk.org
ExploitThird Party Advisory
Source: patrick@puiterwijk.org
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory

Timeline

No history available yet.