radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parsetypedef in typedwarf.c via a malformed DWATname in the .debug_info section (CVE-2020-16269).
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in rx509parsealgorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGEDIRECTORYENTRYSECURITY (CVE-2020-17487).
Also, the radare2-cutter package has been switched to a new upstream that uses a different versioning scheme.