CVE-2025-1786
CVE-2025-1786
Título es
CVE-2025-1786
Sáb, 01/03/2025 – 10:15
Tipo
CWE-119
Gravedad v2.0
4.30
Gravedad 2.0 Txt
MEDIUM
Título en
CVE-2025-1786
Descripción en
A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library /librz/bin/pdb/pdb.c. The manipulation of the argument -P leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.0 is able to address this issue. It is recommended to upgrade the affected component.
01/03/2025
01/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vector CVSS:3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vector CVSS:2.0
AV:L/AC:L/Au:S/C:P/I:P/A:P
Gravedad 4.0
4.80
Gravedad 4.0 txt
MEDIUM
Gravedad 3.1 (CVSS 3.1 Base Score)
5.30
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/rizinorg/rizin/issues/4893
https://github.com/rizinorg/rizin/milestone/18
https://github.com/user-attachments/files/18765730/rz-bin-6fb50-poc.zip
https://vuldb.com/?ctiid_298007=
https://vuldb.com/?id_298007=
https://vuldb.com/?submit_502317=
Enviar en el boletín
Off