CVE-2019-14745

HIGH

Radare2 < 3.7.0 - Command Injection

Title source: rule
STIX 2.1

Description

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

Exploits (1)

nomisec WORKING POC 2 stars
by xooxo · poc
https://github.com/xooxo/CVE-2019-14745

References (6)

Core 6
Core References
Exploit, Third Party Advisory x_refsource_misc
https://bananamafia.dev/post/r2-pwndebian/
Patch, Third Party Advisory x_refsource_misc
https://github.com/radare/radare2/pull/14690

Scores

CVSS v3 7.8
EPSS 0.0708
EPSS Percentile 91.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (4)
fedoraproject/fedora 29
fedoraproject/fedora 30
fedoraproject/fedora 31
radare/radare2 < 3.7.0
Published Aug 07, 2019
Tracked Since Feb 18, 2026