The storeversioninfognuverdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (rread_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.
[
{
"deprecated": false,
"source": "https://github.com/radareorg/radare2/commit/21a6f570ba33fa9f52f1bba87f07acc4e8c178f4",
"id": "CVE-2017-15385-be59f387",
"digest": {
"threshold": 0.9,
"line_hashes": [
"249834045648730063869390483032930089106",
"148782493275075219587103311750097472538",
"21573361315651722192650659714179615612",
"204198373161987429517185941903285709253",
"107985479052894502480335726527024513893",
"213484504598811286621263680179477650847",
"318197996476031419115233673348128354484",
"33293785262724673507625626732766174827"
]
},
"target": {
"file": "libr/bin/format/elf/elf.c"
},
"signature_type": "Line",
"signature_version": "v1"
}
]