Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-43814

Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when reversing an AMD64 ELF binary with DWARF debug info. When a malicious AMD64 ELF binary is opened by a victim user, Rizin may crash or execute unintended actions. No workaround are known and users are advised to upgrade.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.5%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 6.8
Products affected by CVE-2021-43814
  • Rizin » Rizin » Version: N/A
    cpe:2.3:a:rizin:rizin:-
  • Rizin » Rizin » Version: 0.1.0
    cpe:2.3:a:rizin:rizin:0.1.0
  • Rizin » Rizin » Version: 0.1.1
    cpe:2.3:a:rizin:rizin:0.1.1
  • Rizin » Rizin » Version: 0.1.2
    cpe:2.3:a:rizin:rizin:0.1.2
  • Rizin » Rizin » Version: 0.2.0
    cpe:2.3:a:rizin:rizin:0.2.0
  • Rizin » Rizin » Version: 0.2.1
    cpe:2.3:a:rizin:rizin:0.2.1
  • Rizin » Rizin » Version: 0.3.0
    cpe:2.3:a:rizin:rizin:0.3.0
  • Rizin » Rizin » Version: 0.3.1
    cpe:2.3:a:rizin:rizin:0.3.1


Contact Us

Shodan ® - All rights reserved