Vulnerabilities > CVE-2022-34520 - NULL Pointer Dereference vulnerability in Radare Radare2 5.7.2

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
radare
CWE-476

Summary

Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.

Vulnerable Configurations

Part Description Count
Application
Radare
1

Common Weakness Enumeration (CWE)