CVE-2021-4022
 
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address.
Se ha encontrado una vulnerabilidad en rizin. El fallo afecta a un binario ELF64 para la arquitectura HPPA. Cuando un binario especialmente diseñado es analizado por rizin, éste provoca un bloqueo al liberar una dirección de memoria no inicializada (y potencialmente controlada por el usuario, dependiendo de la compilación).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-11-25 CVE Reserved
- 2022-08-25 CVE Published
- 2024-03-17 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-416: Use After Free
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/rizinorg/rizin/issues/2015 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|