Upstream information
Description
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is able to address this issue. The patch is identified as c6c772d2eab692ce7ada5a4227afd50c355ad545. It is recommended to upgrade the affected component.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
CNA (VulDB) | |
---|---|
Base Score | 1.7 |
Vector | AV:L/AC:L/Au:S/C:N/I:N/A:P |
Access Vector | Local |
Access Complexity | Low |
Authentication | Single |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
CNA (VulDB) | SUSE | |
---|---|---|
Base Score | 3.3 | 3.3 |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Attack Vector | Local | Local |
Attack Complexity | Low | Low |
Privileges Required | Low | Low |
User Interaction | None | None |
Scope | Unchanged | Unchanged |
Confidentiality Impact | None | None |
Integrity Impact | None | None |
Availability Impact | Low | Low |
CVSSv3 Version | 3.1 | 3.1 |
CNA (VulDB) | SUSE | |
---|---|---|
Base Score | 4.8 | 4.8 |
Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Attack Vector | Local | Local |
Attack Complexity | Low | Low |
Attack Requirements | None | None |
Privileges Required | Low | Low |
User Interaction | None | None |
Vulnerable System Confidentiality Impact | None | None |
Vulnerable System Integrity Impact | None | None |
Vulnerable System Availability Impact | Low | Low |
Subsequent System Confidentiality Impact | None | None |
Subsequent System Integrity Impact | None | None |
Subsequent System Availability Impact | None | None |
CVSSv4 Version | 4.0 | 4.0 |
SUSE Timeline for this CVE
CVE page created: Mon Feb 17 08:00:14 2025CVE page last modified: Tue Feb 18 13:07:11 2025