Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-27793: Fix unmatched array length in core_java.c (issue #16304) (#16313) · radareorg/radare2@ced0223

An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack.

CVE
#java

@@ -1465,7 +1465,7 @@ static int r_cmd_java_call(void *user, const char *input) {

if (input[4] != ' ') {

return r_cmd_java_handle_help (core, input);

}

for (; i < END_CMDS; i++) {

for (; i < END_CMDS - 1; i++) {

//IFDBG r_cons_printf ("Checking cmd: %s %d %s\n", JAVA_CMDS[i].name, JAVA_CMDS[i].name_len, p);

IFDBG r_cons_printf ("Checking cmd: %s %d\n", JAVA_CMDS[i].name,

strncmp (input+5, JAVA_CMDS[i].name, JAVA_CMDS[i].name_len));

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda