{"id":"CVE-2020-15121","details":"In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.","modified":"2026-04-11T21:19:54.969010Z","published":"2020-07-20T18:15:12.187Z","related":["GHSA-r552-vp94-9358","MGASA-2020-0329"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWC7KNBETYE5MK6VIUU26LUIISIFGSBZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YE77P5RSE2T7JHEKMWF2ARTSJGMPXCFY/"},{"type":"ADVISORY","url":"https://github.com/radareorg/radare2/pull/16966"},{"type":"ADVISORY","url":"https://github.com/radareorg/radare2/security/advisories/GHSA-r552-vp94-9358"},{"type":"ADVISORY","url":"https://github.com/radareorg/radare2/issues/16945"},{"type":"FIX","url":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radare/radare2","events":[{"introduced":"0"},{"fixed":"9d7eda5ec7367d1682e489e92d1be8e37e459296"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"4.5.0"}]}},{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"0"},{"fixed":"04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9"}]}],"versions":["0.10.0","0.10.1","0.10.2","0.10.3","0.10.4","0.10.4-termux4","0.10.5","0.10.6","0.8.6","0.8.8","0.9","0.9.2","0.9.4","0.9.6","0.9.7","0.9.8","0.9.8-rc1","0.9.8-rc2","0.9.8-rc3","0.9.8-rc4","0.9.9","1.0","1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.2.0-git","1.3.0","1.3.0-git","1.4.0","1.5.0","1.6.0","2.0.0","2.0.1","2.1.0","2.2.0","2.4.0","2.5.0","2.6.0","2.6.9","2.7.0","2.8.0","2.9.0","3.0.0","3.0.1","3.1.0","3.1.1","3.1.2","3.1.3","3.2.0","3.2.1","3.3.0","3.4.0","3.4.1","3.5.0","3.5.1","3.6.0","3.7.0","3.7.1","3.8.0","3.9.0","4.0.0","4.1.0","4.1.1","4.2.0","4.2.1","4.3.0","4.3.1","4.4.0","Continuous-Windows","continuous","radare2-windows-nightly","termux"],"database_specific":{"vanir_signatures":[{"target":{"file":"libr/util/str.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-040d6778","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["88308290871752179418798334248132407922","256297085301675615158746693299691841006","31607168942582684448434052486928608219"]},"signature_version":"v1"},{"target":{"file":"shlr/sdb/src/disk.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-0ad1119a","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["102555680954486868044239373284708683698","203547265328797737070926602555475494017","295334694489298952309067500572184076112","138863058546845783300593959985110604056"]},"signature_version":"v1"},{"target":{"file":"libr/bin/pdb/pdb_downloader.c","function":"download"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-183c724e","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"282993450782224922786414648626648155178","length":2791},"signature_version":"v1"},{"target":{"file":"test/unit/test_str.c","function":"all_tests"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-24373455","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"142852979252260211362884195408285815372","length":1047},"signature_version":"v1"},{"target":{"file":"libr/include/r_socket.h"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-258d7c5c","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["144413601346830056451362188347969759115","129493541202340473686722566271413141793","270458363570880565151752627532832008010","26361903190495146276662311000267205635"]},"signature_version":"v1"},{"target":{"file":"shlr/sdb/src/disk.c","function":"r_sys_mkdirp"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-26711bb8","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"262879625237417484159765402181466847680","length":500},"signature_version":"v1"},{"target":{"file":"libr/include/r_util/r_str.h"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-2ddb64ba","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["57155009349029415661102947174546731221","162605962052754499488189190063742086860","150052581027761311489401563567027888267","1360245367252418747055553866600920089"]},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c","function":"r_socket_connect"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-3b82527a","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"498386512604242954943909702397946807","length":3661},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c","function":"r_socket_ready"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-4871f69e","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"230565155893116080136145289061875922876","length":605},"signature_version":"v1"},{"target":{"file":"libr/bin/pdb/pdb_downloader.c","function":"r_bin_pdb_download"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-67513afd","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"32758058504191706792611421832947318484","length":1065},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c","function":"r_socket_accept_timeout"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-71744716","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"66417535173749784104447586808999663941","length":471},"signature_version":"v1"},{"target":{"file":"libr/util/sys.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-75a17ad4","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["20088401449184818540696333942107274677","268849879971437915548927306650740293525","188896349444228122567762427412581888496","257225142598647733752267086328642668182","325193192667794458665339828017111283389","258358102214053277538934218376537294837","213016069435121414166913080400623138613","305669030363168217994310208152128407540","188508361218386536752248142287412070206","219154596454699728572458172105971219116","277785498920567918141549680329458192704","223084564498929700042986958698394577411","47031287726545433781406645730778755431","100391219671791453476517973749303052332","20545562325694196758759111007740194111","4173873772988969641324727977538667169","324192271316732200536897799947376356280","13706770014168656317892289194839854705","141641975196979161459324691109710787761","112873231393537814240280477057960610516","213978384296984799994008302922052136231","306324486592784152842680235122141976745","275370324651908356003432188677002799914","114102401243570255077602113599726656970","294904643129037513087977295527419484359","203547265328797737070926602555475494017","240874770340166351290456661883608570285","41815295896125858904573175370350067436"]},"signature_version":"v1"},{"target":{"file":"test/unit/test_str.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-786340a2","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["3937311854549647749868752653633566987","332045946645790641490747491561924031397","40963584870755831727031728796505545154","254968320943197555773727484634610836470","91014652202175522035401808446032926237","228561789031886887585545513258278757883","131500158719047004842750668269176169352"]},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-789e0372","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["92029746441178509767733425508500906245","161928935507239181557376499993819497135","173305984096162044975644105549134002826","25767433152727457824270782297893117663","82600995706692993765312641991997440560","3864970415608226485914736075959623145","43118187634138016286026447345767839585","237316591235505237822769384496927023767","329357103779749470687830952485687161839","124095201262072052424933298059523919339","137547459868338010544952148881891171588","113342084778822995850112408009820699287","30086850080891191351306785194171345155","72767903796639924971117392898685559301","49262954123850131152378726129789230005","131208078986119884923271661236781292171","73870310847008537723150708909720241236","310824348817359813762005882779223278476","186016590978656336747915927011492598619","201676155476765937690685876081354534958","33523465865736717990213817172645181965","67468493767764569156081622416415374348","140398236077259047432271051523696825210","58757676178868402082313567550848568658","304751556064544287755694196996153511453","287684850793060811944968043651573217371","327321450336791248708330928332925958328","191224191161485797823211854391305538876","301416000381956581804923514516666911499","177095722572122428268199518737712557446","25927016013655177189925798737721103822","71091182795377035549670784251316664583","186623081945375128892444367162944081078","89263956006055527936000741283940803009","303532107801799049641088694071895174759","256527994889884038531487531946642959480","275179500604355358718786290028830115237","205168600995273388521641519363440674818","329290829705847688795538659626548489660","191224191161485797823211854391305538876","301416000381956581804923514516666911499","177095722572122428268199518737712557446","25927016013655177189925798737721103822","147603324187341319463629032405464172887","44395498672298477089786331943616640774","10438533974087531357309173282792206303","1756956458320290887118447293942866593","14497553849875484703006268557786828359","280093170004242696960621166853224891090","91690955628351641090292816637921243936","93310374017938391406978241159932764039","244379516420510060563157456806122177318","190828736010898283080713941299417053772","289941394984404333323139262712554136555","68219763630426239988022156798168966933","40103877105363365924506783923940393470","32653294032129990661359671820598418583","238220032646417635487414155526610145814","3934855577841444032827762752039621350","78644457779154076993028202765741071873","122022245779452246079094135435913806805","207618308113412554646983846074393146125","283669506704332401537275211889898309207","267859945144473861617306739104555415887","40520804559372263288795747006814295479","264315278361039089188888871915978357444","156538231562551525459384154718385931467","221122697059550596920534758009361477310","16595093942453312725111069204237692539","339899084293418896566016248554930863001","64674390732653884159798384258699495696","208754330330603830307478737792436100795","136799455080699367424542867407403303033","329634540561516474308753820673357633199","270516186931949176217751545234269727410","53257095252399221929241490722400561928","303446440843582839178454720093060202525","332681131547511070010886615123742838234","87780987730392747428224509965951878595","79458426935264683942015112374419063056","320582984382180099888469998809119328463","237842633035006004846548042007691168693","221713696547827973837568897759558744954","301912280946691475040760745156567136034","294566991021230902963470042685305067104","322580230820364894183541018569617999705","113425961981534776136557450710310272470","204038442719735143322626734134352117322","182933661888190810876999124319083792692","274755775083304040283507990034245862180","330300172626986484682920140552756018932","103948316332426616481172218634694381062","230952464198487679687339932291364674049","212098632825060241241157291403730451896","66623591123669694541212644130257315612","36172694602458995698400968962821953603","157806959931470442271822679655447029355","92369379839524811619345033948742239682","123218426655200948407708254844431183903","253452093351937351789989665733836208908","173697888223429698715457015181187123291","138292797345732014557747974816097645363","179240133137591387175331101948635052195","215223392263774951795839027544382019787","81394579061875727011007613952767141437","219113028047715480423759614180682014742","247088563443205443583022803040698562460","280275759827392963582789123990784040025","142843866050309124834421652930284132699","71072246775530790963318257481710380433","273303862088524642112890415300567135224","14554561691074132194251679949850646605","15409792009087085189940989090645791801","297115442902217640539532534561005723226","240026519320513433868043082394635255421","133674600197039962979127998040101772007","287597934808476362853859486719349890373","224642398325171240413653509439620225919","148103311616009394823898434629911948669","61866642583629914403225229729361707196","19166165519361116035445224950711948793","26240421064691665789292067931364383587","125162423322646721550874813905316698075","325963362930881697127390941374795626703","116068962027531371705066656585298921898","158603727673653141184195870678903311607","291234046714599196525715301930311763211","164526457145581661024180821294146628657","234073775078069427702635281191857637135","225448558722030469076054621340321822224","193274387945125273807982896497385552565","90954520596106553907912292539343402855","145888289125263888440207555572204589951","117829356376979395997992243995711247917","47651574552298627391154359963266432393","108253864970459129388035297613731508237","14495550425978431141741112715813701195","21809955864216798662029556099203644589","89803261942047466474296942241393022701","195610761305572937415265966029380082721","76263024350736793111021108542665041087","134400135835389825756332999345144731061","78288064467807420421778182281536309557","39457343766299887284455210530863251782","192933364676336529818153854670655662497","22754473538797224819452078053177076123","305254364209091630536649297582726075119","44879193502767355678310056411210020628","267713120809794819624034554392490941376","223978237981694243916400547803973231975","121559745152474988905813942728775042071","28048429346654836143962919686027329530","90227923215441292144602796388812920910","162463728803289893252504582816802373451","6080959694800955104120492468212276468","110304955171314833883629491742033669768","139613252038400495257249704460576470042","165503559929723206604644937679854166592","141768569548026675255528545673472222300","324262093440812516464978025378879596549","149618094734998231670069456771670391751","28771375179901525829889731107490942722"]},"signature_version":"v1"},{"target":{"file":"libr/socket/socket_http.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-78ea7228","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["222567010671610279344808819819738468100","320536440922516110290650165836762046279","182574357151874940690149769086070644832","127536794943895373652593993920571449532","4381508134932000462697650343062302276","22209192107029090406454434220931761916","11303891949208752519850828484962239493","278269104817511785056394441719087566350","4713825767870885789448292361763743146","23152900526535382937132254856162655788","312860833852554322806008108361926604924","265616454446001290945182393594292181986","6656206681675202602103473899095946942","239776770259327976773677399319277334803","158634641867372067517945965749402276120","257485742865403639258528486829570552006","99346502242704097874884625384992746387","14342227665973783989157462756774128469","111992830513017697851790938290925262619","194331083288508403241576662339257137632","227321892251212598995100471352039061862","275031099859748116363755741830608121939","212662054025420311297475994426767868988","170048162610564147174819001064978232237","34422864733112142770819617939549094182","173715309528758323426792077762801862206","250420289476574182610425339045192749319","17605727826033400721463349485995031351","277371072803012369784589929858404875026","81399822703568417300828881092740760323","236345234738488770437806318326568156049","221963097632886879818487425894189249896","151349973118816139237952848836127471073","333794489624490926843705541208420566979","92079467231420885221542251563486186830","10544640612877209536638736458592108294","18185160250083884816340135634527414203","128593275526659625988327699192454595820","82610257478587006677105403896669234652","266343692524684788939419613397187570039","13291460686546943992461923197538481245","74961855160660054254922901931786574212","308491340452302702688585244764422482811","19398065517927683319961412221028948368","197210323741665667858138463364620419813","113541905093585150004509884556630840119","52588934021473874333223956481187002131","250117686943453644650619779887470932403","172750079388462900946902314723588803900","4119579271895877712944807279779742213","94780593406293273882662002179797987064","100998793108114423594947597867423594055","101739380300029683079224919494934655837","201706350615254698547706909287868830181","192618103812171373610999590115464567979","57325112471271334507802977446054761703","23389216974157505058471421081958482728","212079275075061163343805265183527914862","320256928350847953876712373540694628840","219412387102288901278913750881847353765","32095534395282105572438222185763815777","235837131593216644369072639592820852031","14472334358108622273964003468791172397","283359625229425365395615456632159860841","310954525840187267340877891097684851738","245251521189361594955803371621224265621","227328699360976930872575587746094943596","164274819342667872118792998532134213248","60128082460843676260314440682804901998","223074726414075569025300380535099012882","273477056924447282326045990513241161927","269638698022451452730058723211784776047","339493076012192173015277836398906553260","301929797866133111285640863917591108546","337229479697087064276079227031437914757","339975698319550791458202253386615768821","143262229351555398560429291891093137805","193755200583149898475537223887452963626","302088285641719165864897694683544133047","225415585866233756067551738953419802680","47982413589489131071098337782415295050","198849035373163897832039945941420119227","188552092533652544103172440943931457214","272444234606660197330182137123098733812","257523591932835480840621109822970481172","35157213982412209347911090614518745778","258014245948788074473212582308355493141","162967735927692259867931416713116996266","76167996828643406060518414624285255585","280151778973409983282139917506651235778","281748067384426144308170610088923315019","38225444924468039865101410237730441038","136681604929889014367347250046524592659","238284850335859020227999126682803540663","334988691865371686211396149710617291575"]},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c","function":"r_socket_read_block"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-8be978c2","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"279372533987290729639380483985911018181","length":267},"signature_version":"v1"},{"target":{"file":"libr/bin/pdb/pdb_downloader.c","function":"checkCurl"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-9eee1691","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"120928271875528890924127685304079022089","length":153},"signature_version":"v1"},{"target":{"file":"libr/socket/socket_http.c","function":"r_socket_http_post"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-b1cac9ff","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"125778718690127667700083443383025496058","length":1191},"signature_version":"v1"},{"target":{"file":"libr/include/r_types.h"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-b4e5938e","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["35117786600509367233020353533807827893","28580038231809106737506151967754363181","245593363929788042784026444725091059281","278013250585279799572336221350162996494"]},"signature_version":"v1"},{"target":{"file":"libr/socket/socket_http.c","function":"__socket_slurp"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-c316676b","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"49616633693494413832461138865015850794","length":402},"signature_version":"v1"},{"target":{"file":"libr/bin/pdb/pdb_downloader.c"},"signature_type":"Line","deprecated":false,"id":"CVE-2020-15121-c7b0b9ba","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"threshold":0.9,"line_hashes":["141197845587282220509917219573801993184","297403444984144019351074625422475023250","314437866721291980672279019051632401397","2832070166042404918342109145034069693","104171893040781985100580368638462283696","163638649111165154016949897207752068954","105135349804760838859480469610730392589","31243672228104643960808119416533677578","98696803197568406130559787669604337592","261833646571630105588244920013274637967","232366882752923365039189747267551457088","82788671396857344220494957683558532371","82007230866268788214926738403378418745","128670317899023119181038014327729217510","144589193018209043203206567990555646877","141901172188506798777913459649446084240","69047047003694900995776421394379267202","329642921163986880839472368936523492238","31678230461532654414548366875262019945","7036333340497440327598615297040249015","233533654996511845607912750708749270888","158884289034250319935209641425549623363","180117682314999107385719789184282283113","107700030613950230052790957998323157802","125656533414899236014174681407365914420","303122528120015717224975978771766229237","125178967030413643637370637484636017551","104355934913294150482852123643284475185","156941771162608276970821252711021960042","57586395022418395741894932682251078153","242018284978223877236070135037152970175","155833027084304826519472719554369816317","129213332557955732455844778590354721296","201573327261505578040916267276255345496","286806059015009149926579714564715766116","175807096706484765109734196731887186463","330566150403833244575840214046087401084","227357640504211159903409295523971123538","144564022568916271228586647323894317381","206997134062529710157609767926287279714","38274205727689202899594863436288582406","174672094366423762733970529724657756334","124421727715451124564894783117540068205","179518782168222064592299508158996610519","274841076274618045895900676193167048730","23841926368478121105545345613462991861","75500519789995463999361712534475034963","56053836727832674398974103384914358542","248851393082787071398029460561136372785","175554984780013224310887249576243911420","28293950184065927980690453728360172399","141286987143647578868432016647254693379","313205558985167794274375645255661734935","195006160486240410830962475989626376586","155961673635785133674678917661511803718","223250654229012340967241947097874033964","154253210315336158278549999573391327515","332631795197266299562176332530107665330","176395913979330807785664848661348776883","137646644630006262853540511265801497900","252213740268590512936082980947571868039","281643893872859079369021011007832531991","230042794125106546796600190973288121623","81759875996997258058363584120926671111","43380949754558829967569384109280586415","94685069920834520860362794989034018388","120144512184037829386091656677181092394","104269408387915678979904564985268424269","200296629087508726320739903923195219678","249122637396521844387204153980432329370","266949452769899222163911140803223378279","99367621960158795743908233778139520174","337318104734110874512099228525547490232","31685226586611188455151636034550875719","225437782079999937879371285152338081391","149721393767329662897926802088483742384","178912097170015891260897983413462290359","49129806596643476663843026990788651512","46063046637697178497649467240173184212","24199118040639034168387515982053727555","285007044835809987239563451802334160100","137513736116404932532958755811502617419","171832792401260687609623094145629131661","204123205666608208713945433970752582232","93085210589756273883115054761704184473","108668250577056872955140576492441446859","224356507172899335777924713847528045229","301913251655408641656965547187887146321","220294194827476298190229864916009227090","161555933550966204451250752263023881302","47313712375136000990051115387277722599","280239295507009148166152920842997812882","40898092002894370664586920593853868299","61667116871380499224096103813530799391","123864958855290347287362447255369887957","131407193144430987346657070977943809909","169908023092327873061345033818545250320","225776917790750981622072003194417676943","81179070266915312181252617632823449379","36308347225336886772983685884748357032","286159582674268405004772433307927576910","220033402325010259274215042043615685803","220633171993547510336449699215116870406","294181976651552034462842025998197108110","158896149413191306848572357001150702415","67786331739477324556093018671335317043","239155805126873226614140721124591418760","173076212143767646189068704473924047416","48638808584597198611927396279324096382","238308562355421662828821263095433109102","245019792125365578932181775766311910003","222389132097682132111949103110585737373","256642638168205645209017039591776229014","301913251655408641656965547187887146321","41583510739143044332233863713642784449","109982743712430183240193698116705474282","78533140780541022422357014363042998239","230231426063347645035150387685588206492","207861823086416959857259265958154577428","169078640806232852889202362446817339695","106918171454049776634558594629773023608","165416990281619951466402875845163602669","219679465723576560648375591842330151190","85456222658124435564820666385784166857","134267319755606898060746555376229275","56492829235043621562440063076499659120","211897008389955891183604348788785913111","62444065534643145646436211071581436908","333717384478489575059073512712678059010","146936319299534652321155060285526061652","184095740521284508081216908405728557603","323405000183027459537036347580556614594","169921288312202022316708930166258136926","133830584095417243712313451502881314574","94608958416923012500933928430812475719"]},"signature_version":"v1"},{"target":{"file":"libr/util/sys.c","function":"r_sys_cmd_str_full"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-cde8c3b8","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"290664995853919261753582056330900868125","length":2725},"signature_version":"v1"},{"target":{"file":"libr/socket/socket_http.c","function":"r_socket_http_get"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-d1e109f2","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"331823516328454728268785735760161062932","length":1473},"signature_version":"v1"},{"target":{"file":"libr/socket/socket_http.c","function":"r_socket_http_answer"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-d64b2b65","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"307979726942053660928643717421928025678","length":1132},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c","function":"r_socket_read"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-e19e3dc0","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"101368236248505948208794132818964098058","length":643},"signature_version":"v1"},{"target":{"file":"libr/socket/socket.c","function":"r_socket_block_time"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-e7737c6f","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"105979470602117731296739407876212953374","length":707},"signature_version":"v1"},{"target":{"file":"libr/util/sys.c","function":"r_sys_mkdirp"},"signature_type":"Function","deprecated":false,"id":"CVE-2020-15121-f968eebf","source":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","digest":{"function_hash":"50324848660237895190634080565371311385","length":772},"signature_version":"v1"}],"vanir_signatures_modified":"2026-04-11T21:19:54Z","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"31"}]},{"events":[{"introduced":"0"},{"last_affected":"32"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15121.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}