radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Radare2 | Radare | * | 4.0.0 (including) |
Radare2 | Ubuntu | bionic | * |
Radare2 | Ubuntu | disco | * |
Radare2 | Ubuntu | eoan | * |
Radare2 | Ubuntu | esm-apps/bionic | * |
Radare2 | Ubuntu | esm-apps/xenial | * |
Radare2 | Ubuntu | lunar | * |
Radare2 | Ubuntu | trusty | * |
Radare2 | Ubuntu | upstream | * |
Radare2 | Ubuntu | xenial | * |