TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-3674

HIGH
7.8

Description

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

Details CVE

Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie3/24/2023
Derniere modification2/25/2025
Sourcenvd
Observations honeypot0

Produits affectes

rizin:rizin

Faiblesses (CWE)

CWE-119CWE-125CWE-125

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.