Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-15121

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.6%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 6.8
References
Products affected by CVE-2020-15121
  • Radare » Radare2 » Version: 0.10.0
    cpe:2.3:a:radare:radare2:0.10.0
  • Radare » Radare2 » Version: 0.10.1
    cpe:2.3:a:radare:radare2:0.10.1
  • Radare » Radare2 » Version: 0.10.2
    cpe:2.3:a:radare:radare2:0.10.2
  • Radare » Radare2 » Version: 0.10.3
    cpe:2.3:a:radare:radare2:0.10.3
  • Radare » Radare2 » Version: 0.10.4
    cpe:2.3:a:radare:radare2:0.10.4
  • Radare » Radare2 » Version: 0.10.5
    cpe:2.3:a:radare:radare2:0.10.5
  • Radare » Radare2 » Version: 0.10.6
    cpe:2.3:a:radare:radare2:0.10.6
  • Radare » Radare2 » Version: 0.8.6
    cpe:2.3:a:radare:radare2:0.8.6
  • Radare » Radare2 » Version: 0.8.8
    cpe:2.3:a:radare:radare2:0.8.8
  • Radare » Radare2 » Version: 0.9
    cpe:2.3:a:radare:radare2:0.9
  • Radare » Radare2 » Version: 0.9.2
    cpe:2.3:a:radare:radare2:0.9.2
  • Radare » Radare2 » Version: 0.9.4
    cpe:2.3:a:radare:radare2:0.9.4
  • Radare » Radare2 » Version: 0.9.6
    cpe:2.3:a:radare:radare2:0.9.6
  • Radare » Radare2 » Version: 0.9.7
    cpe:2.3:a:radare:radare2:0.9.7
  • Radare » Radare2 » Version: 0.9.7.3-1
    cpe:2.3:a:radare:radare2:0.9.7.3-1
  • Radare » Radare2 » Version: 0.9.8
    cpe:2.3:a:radare:radare2:0.9.8
  • Radare » Radare2 » Version: 0.9.9
    cpe:2.3:a:radare:radare2:0.9.9
  • Radare » Radare2 » Version: 1.0
    cpe:2.3:a:radare:radare2:1.0
  • Radare » Radare2 » Version: 1.0.0
    cpe:2.3:a:radare:radare2:1.0.0
  • Radare » Radare2 » Version: 1.0.1
    cpe:2.3:a:radare:radare2:1.0.1
  • Radare » Radare2 » Version: 1.0.2
    cpe:2.3:a:radare:radare2:1.0.2
  • Radare » Radare2 » Version: 1.1.0
    cpe:2.3:a:radare:radare2:1.1.0
  • Radare » Radare2 » Version: 1.2.0
    cpe:2.3:a:radare:radare2:1.2.0
  • Radare » Radare2 » Version: 1.2.1
    cpe:2.3:a:radare:radare2:1.2.1
  • Radare » Radare2 » Version: 1.3.0
    cpe:2.3:a:radare:radare2:1.3.0
  • Radare » Radare2 » Version: 1.4.0
    cpe:2.3:a:radare:radare2:1.4.0
  • Radare » Radare2 » Version: 1.5.0
    cpe:2.3:a:radare:radare2:1.5.0
  • Radare » Radare2 » Version: 1.6.0
    cpe:2.3:a:radare:radare2:1.6.0
  • Radare » Radare2 » Version: 2.0.0
    cpe:2.3:a:radare:radare2:2.0.0
  • Radare » Radare2 » Version: 2.0.1
    cpe:2.3:a:radare:radare2:2.0.1
  • Radare » Radare2 » Version: 2.1.0
    cpe:2.3:a:radare:radare2:2.1.0
  • Radare » Radare2 » Version: 2.2.0
    cpe:2.3:a:radare:radare2:2.2.0
  • Radare » Radare2 » Version: 2.3.0
    cpe:2.3:a:radare:radare2:2.3.0
  • Radare » Radare2 » Version: 2.4.0
    cpe:2.3:a:radare:radare2:2.4.0
  • Radare » Radare2 » Version: 2.5.0
    cpe:2.3:a:radare:radare2:2.5.0
  • Radare » Radare2 » Version: 2.6.0
    cpe:2.3:a:radare:radare2:2.6.0
  • Radare » Radare2 » Version: 2.6.9
    cpe:2.3:a:radare:radare2:2.6.9
  • Radare » Radare2 » Version: 2.7.0
    cpe:2.3:a:radare:radare2:2.7.0
  • Radare » Radare2 » Version: 2.8.0
    cpe:2.3:a:radare:radare2:2.8.0
  • Radare » Radare2 » Version: 2.9.0
    cpe:2.3:a:radare:radare2:2.9.0
  • Radare » Radare2 » Version: 3.0.0
    cpe:2.3:a:radare:radare2:3.0.0
  • Radare » Radare2 » Version: 3.0.1
    cpe:2.3:a:radare:radare2:3.0.1
  • Radare » Radare2 » Version: 3.1.0
    cpe:2.3:a:radare:radare2:3.1.0
  • Radare » Radare2 » Version: 3.1.1
    cpe:2.3:a:radare:radare2:3.1.1
  • Radare » Radare2 » Version: 3.1.2
    cpe:2.3:a:radare:radare2:3.1.2
  • Radare » Radare2 » Version: 3.1.3
    cpe:2.3:a:radare:radare2:3.1.3
  • Radare » Radare2 » Version: 3.2.0
    cpe:2.3:a:radare:radare2:3.2.0
  • Radare » Radare2 » Version: 3.2.1
    cpe:2.3:a:radare:radare2:3.2.1
  • Radare » Radare2 » Version: 3.3.0
    cpe:2.3:a:radare:radare2:3.3.0
  • Radare » Radare2 » Version: 3.4.0
    cpe:2.3:a:radare:radare2:3.4.0
  • Radare » Radare2 » Version: 3.4.1
    cpe:2.3:a:radare:radare2:3.4.1
  • Radare » Radare2 » Version: 3.5.0
    cpe:2.3:a:radare:radare2:3.5.0
  • Radare » Radare2 » Version: 3.5.1
    cpe:2.3:a:radare:radare2:3.5.1
  • Radare » Radare2 » Version: 3.6.0
    cpe:2.3:a:radare:radare2:3.6.0
  • Radare » Radare2 » Version: 3.7.0
    cpe:2.3:a:radare:radare2:3.7.0
  • Radare » Radare2 » Version: 3.7.1
    cpe:2.3:a:radare:radare2:3.7.1
  • Radare » Radare2 » Version: 3.8.0
    cpe:2.3:a:radare:radare2:3.8.0
  • Radare » Radare2 » Version: 3.9.0
    cpe:2.3:a:radare:radare2:3.9.0
  • Radare » Radare2 » Version: 4.0.0
    cpe:2.3:a:radare:radare2:4.0.0
  • Radare » Radare2 » Version: 4.1.0
    cpe:2.3:a:radare:radare2:4.1.0
  • Radare » Radare2 » Version: 4.1.1
    cpe:2.3:a:radare:radare2:4.1.1
  • Radare » Radare2 » Version: 4.2.0
    cpe:2.3:a:radare:radare2:4.2.0
  • Radare » Radare2 » Version: 4.2.1
    cpe:2.3:a:radare:radare2:4.2.1
  • Radare » Radare2 » Version: 4.3.0
    cpe:2.3:a:radare:radare2:4.3.0
  • Radare » Radare2 » Version: 4.3.1
    cpe:2.3:a:radare:radare2:4.3.1
  • Radare » Radare2 » Version: 4.4.0
    cpe:2.3:a:radare:radare2:4.4.0
  • Fedoraproject » Fedora » Version: 31
    cpe:2.3:o:fedoraproject:fedora:31
  • Fedoraproject » Fedora » Version: 32
    cpe:2.3:o:fedoraproject:fedora:32


Contact Us

Shodan ® - All rights reserved