A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a patch to resolve this issue.
0.9.6-3.1ubuntu15.9.8+dfsg-25.9.8+dfsg-2ubuntu0.25.10.15.9.8+dfsg-2ubuntu0.25.10.25.9.8+dfsg-26.0.4+dfsg-16.0.7+ds-11.6.0+dfsg-12.0.0+dfsg-12.1.0+dfsg-12.3.0+dfsg-12.3.0+dfsg-22.3.0+dfsg-2ubuntu0.1~esm13.2.1+dfsg-5build14.0.0+dfsg-14.2.1+dfsg-14.2.1+dfsg-24.2.1+dfsg-2ubuntu0.1~esm15.5.0+dfsg-1.1ubuntu25.5.0+dfsg-1.1ubuntu35.5.0+dfsg-1.1ubuntu3+esm15.5.0+dfsg-1ubuntu1Exploitability
AV:LAC:LAT:NPR:LUI:NVulnerable System
VC:NVI:NVA:LSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P