high · CVSS v3 6.3 · CVSS v4 5.3
CVE-2026-94090
JusticeRage Manalyze 1.0.0 contains a remote integer underflow in the PE::_parse_debug function that can corrupt memory or crash the parser.
Overview
JusticeRage Manalyze 1.0.0 contains a remote integer underflow in the PE::_parse_debug function that can corrupt memory or crash the parser. The flaw allows attackers to manipulate the misc.Length argument, potentially leading to denial of service or unintended data exposure. Prompt patching is essential to mitigate these risks.
Description
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue.
Impact
Confidentiality: memory corruption could expose sensitive data. Integrity: altered PE parsing may lead to incorrect execution or data tampering. Availability: the flaw can cause crashes, denying service. Defenders: system administrators and security teams managing JusticeRage installations are directly impacted.
Remediation
Apply the vendor patch identified by commit 3e299685759f4f767088871de58c5d07f98ee382. If the patch is not yet available, restrict network access to the PE Parser component or disable remote PE parsing until the update is applied.
Risk context
High severity with CVSS 6.3 indicates a significant threat; immediate remediation is recommended.
Affected products
- JusticeRage Manalyze 1.0.0
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 6.3
- CVSS v4
- 5.3
- EPSS
- —