{"id":"MGASA-2020-0329","summary":"Updated radare2 packages fix security vulnerability","details":"In radare2 before version 4.5.0, malformed PDB file names in the PDB server\npath cause shell injection. To trigger the problem it's required to open the\nexecutable in radare2 and run idpd to trigger the download. The shell code will\nexecute, and will create a file called pwned in the current directory\n(CVE-2020-15121).\n\nThe radare2 package has been updated to version 4.5.0, fixing these issues and\nother bugs.\n\nAlso, the radare2-cutter package has been updated to version 1.11.0.\n","modified":"2026-04-16T04:41:19.708711550Z","published":"2020-08-18T17:41:27Z","upstream":["CVE-2020-15121"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0329.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27060"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7OFOJ23B5CP5XDVYTW6TTN7OFZPAIVY4/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MWC7KNBETYE5MK6VIUU26LUIISIFGSBZ/"}],"affected":[{"package":{"name":"radare2","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/radare2?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0329.json"}},{"package":{"name":"radare2-cutter","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/radare2-cutter?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0329.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}