{"id":"CVE-2017-9520","details":"The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.","modified":"2026-08-07T14:53:51.055863Z","published":"2017-06-08T14:29:00.297Z","references":[{"type":"REPORT","url":"https://github.com/radare/radare2/issues/7698"},{"type":"FIX","url":"https://github.com/radare/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"91daa516ebf44f0bc422c1f6054a1938df16e25f"},{"last_affected":"91daa516ebf44f0bc422c1f6054a1938df16e25f"},{"fixed":"f85bc674b2a2256a364fe796351bc1971e106005"}],"database_specific":{"cpe":"cpe:2.3:a:radare:radare2:1.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.0"},{"last_affected":"1.5.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9520.json","vanir_signatures_modified":"2026-08-07T14:53:51Z","vanir_signatures":[{"target":{"file":"libr/core/cbin.c","function":"r_core_bin_set_env"},"deprecated":false,"digest":{"function_hash":"176287331169048068014519446979246965043","length":893},"id":"CVE-2017-9520-1463369f","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005"},{"target":{"file":"libr/config/config.c","function":"r_config_set"},"deprecated":false,"digest":{"function_hash":"79059203780100655889398475173598585289","length":1930},"id":"CVE-2017-9520-be45c11b","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005"},{"id":"CVE-2017-9520-cc79945f","signature_type":"Line","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005","target":{"file":"libr/core/cbin.c"},"deprecated":false,"digest":{"line_hashes":["183791960127587604471889937694274189674","57223251238555722903857489874342925678","151346299546101784559683188854030576818","9469576686545819922152056240732335509","168437269123251131135648102425443210261","171268881786570126763085531274021807282","183076540113215773977108581591329750216","139522883623943474150755828260568668573","244228412977303805997622847917959312104","90093344064419229953054741697190315777","193000678024019727056034168462441056463","108551911977570361293114646678935623993","135816300997801231492817413148454024734","229252909839171956753031330525572505783","110058798846098240349233660364733601142"],"threshold":0.9}},{"source":"https://github.com/radareorg/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005","target":{"file":"libr/config/config.c"},"deprecated":false,"digest":{"line_hashes":["308598182805312281522945467344897079410","8760821368833630665576212967798831100","185133641519768264065842165951575381637","307771205038602884228326919546396902459","37003960473275799048736045447338720011"],"threshold":0.9},"id":"CVE-2017-9520-dfab808d","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}