rootpwn

high · CVSS v3 6.3 · CVSS v4 5.3

CVE-2026-94090

JusticeRage Manalyze 1.0.0 contains a remote integer underflow in the PE::_parse_debug function that can corrupt memory or crash the parser.

Overview

JusticeRage Manalyze 1.0.0 contains a remote integer underflow in the PE::_parse_debug function that can corrupt memory or crash the parser. The flaw allows attackers to manipulate the misc.Length argument, potentially leading to denial of service or unintended data exposure. Prompt patching is essential to mitigate these risks.

Description

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue.

Impact

Confidentiality: memory corruption could expose sensitive data. Integrity: altered PE parsing may lead to incorrect execution or data tampering. Availability: the flaw can cause crashes, denying service. Defenders: system administrators and security teams managing JusticeRage installations are directly impacted.

Remediation

Apply the vendor patch identified by commit 3e299685759f4f767088871de58c5d07f98ee382. If the patch is not yet available, restrict network access to the PE Parser component or disable remote PE parsing until the update is applied.

Risk context

High severity with CVSS 6.3 indicates a significant threat; immediate remediation is recommended.

Affected products

  • JusticeRage Manalyze 1.0.0

Scores

Severity
high
CVSS v2
7.5
CVSS v3
6.3
CVSS v4
5.3
EPSS

integer-underflow remote PE-parser high-severity patch justice-rage

← All CVEs