PoC Index

CVE-2019-14745

HIGH 7.8EPSS 4.4%

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
4.41% chance of exploitation in the next 30 days, 91th percentile
Published
2019-08-07
Updated
2024-08-05

Proof-of-concept exploits (2)

References

Related