Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
radare2 < 6.1.4 Command Injection via PDB Parser print_gvars()
Vulnerability Description
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Radare2 安全漏洞
Vulnerability Description
Radare2是Radare开源的一个面向 Unix 极客的 Libre 反向框架。 Radare2 6.1.4之前版本存在安全漏洞,该漏洞源于PDB解析器的print_gvars函数存在命令注入问题,可能导致任意命令执行。
CVSS Information
N/A
Vulnerability Type
N/A