The stringscanrange() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
[
{
"digest": {
"length": 3308.0,
"function_hash": "98494690071503454194797992045746234891"
},
"id": "CVE-2018-11381-49ee0dbb",
"source": "https://github.com/radareorg/radare2/commit/3fcf41ed96ffa25b38029449520c8d0a198745f3",
"signature_type": "Function",
"target": {
"file": "libr/bin/file.c",
"function": "string_scan_range"
},
"signature_version": "v1",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"21929376789596439544151635748175387463",
"135304949598820514148528422986955564816",
"90893773958739721628432767542698805236",
"167433008854843717354377112139355015952",
"131646173151381651989664268400677323778",
"75315884126951106224382910493167852627",
"110624375282005136507287153677307465291",
"75923100023603709790442625293417595952",
"128907132257500091596400469582241022120",
"190621870524681049041393540565297254899",
"64097654862288902144494563974971199337",
"122613457145837381517861684281175157753",
"254739571038874113869306874845254548663"
]
},
"id": "CVE-2018-11381-d4ac1eeb",
"source": "https://github.com/radareorg/radare2/commit/3fcf41ed96ffa25b38029449520c8d0a198745f3",
"signature_type": "Line",
"target": {
"file": "libr/bin/file.c"
},
"signature_version": "v1",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11381.json"