The parseimportptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11380.json"
[
{
"deprecated": false,
"target": {
"file": "libr/bin/format/mach0/mach0.c"
},
"digest": {
"line_hashes": [
"80106584270825631491133252677064656249",
"120595454921800453152094682305794221927",
"265235334238004593011061893422902192785",
"292377935732633789539500106500842017735",
"12172402049165564365953000525221078311",
"173774097433309801077127699316139649887",
"339148718153184470647559306553667717033",
"188007267734801562862173717071087923880",
"7146839840787778039268620082578298543",
"275826814133754856247121549820614993996",
"16908616621380176580153284427625848037",
"300988715257844789395193896869795358009",
"77575065302905979402957953564941426435",
"139305347815845869349769479274379068445",
"226925157809374810993164457549071889141",
"217547019326275212636302716947592763967",
"267067359882831628602474630980210216093",
"215231667367959711567646516132732964613"
],
"threshold": 0.9
},
"id": "CVE-2018-11380-01a96fe3",
"signature_type": "Line",
"source": "https://github.com/radareorg/radare2/commit/60208765887f5f008b3b9a883f3addc8bdb9c134",
"signature_version": "v1"
}
]