CVE-2025-1786 – Rizin Rizin PDB Buffer Overflow Vulnerability

The following table lists the changes that have been made to the
CVE-2025-1786 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 01, 2025

    Action Type Old Value New Value
    Added Description A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library /librz/bin/pdb/pdb.c. The manipulation of the argument -P leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.0 is able to address this issue. It is recommended to upgrade the affected component.
    Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
    Added CVSS V2 (AV:L/AC:L/Au:S/C:P/I:P/A:P)
    Added CWE CWE-119
    Added CWE CWE-120
    Added Reference https://github.com/rizinorg/rizin/issues/4893
    Added Reference https://github.com/rizinorg/rizin/milestone/18
    Added Reference https://github.com/user-attachments/files/18765730/rz-bin-6fb50-poc.zip
    Added Reference https://vuldb.com/?ctiid.298007
    Added Reference https://vuldb.com/?id.298007
    Added Reference https://vuldb.com/?submit.502317
Share the Post:

Related Posts