Lucene search

K
osvGoogleOSV:CVE-2020-15121
HistoryJul 20, 2020 - 6:15 p.m.

CVE-2020-15121

2020-07-2018:15:12
Google
osv.dev
6
radare2
pdb
shell injection
cve-2020-15121
security vulnerability
software

AI Score

7

Confidence

Low

EPSS

0.013

Percentile

85.8%

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it’s required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.

AI Score

7

Confidence

Low

EPSS

0.013

Percentile

85.8%