CVE-2019-14745: Fedoraproject Fedora

High severity, CVSS 7.8. EPSS: 4.5% chance of exploitation in the next 30 days.

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

Affected products

  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Radare RADARE2: before 3.7.0 (fixed in 3.7.0)

Published 2019-08-07. Last modified 2026-06-17.