VDB

GCVE-110-MAGEIA-2020-329

GCVE-110-MAGEIA-2020-329
Advisory Published
Vulnetix · Advisory published August 18, 2020
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory (CVE-2020-15121). The radare2 package has been updated to version 4.5.0, fixing these issues and other bugs. Also, the radare2-cutter package has been updated to version 1.11.0.

Affected Products

VendorProductVersionsPlatforms
Mageiaradare20 (affected), 4.5.0-1.mga7 (unaffected)
Mageiaradare2-cutter0 (affected), 1.11.0-1.mga7 (unaffected)

Browse GCVE Records

74,147 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›