There is a heap out of bounds read in radare2 2.6.0 in 6502op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.
[
{
"id": "CVE-2018-12322-a966b10f",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/bbb4af56003c1afdad67af0c4339267ca38b1017",
"signature_type": "Function",
"digest": {
"function_hash": "180132918625121190672768699203791564937",
"length": 11727.0
},
"deprecated": false,
"target": {
"function": "_6502_op",
"file": "libr/anal/p/anal_6502.c"
}
},
{
"id": "CVE-2018-12322-c7001545",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/bbb4af56003c1afdad67af0c4339267ca38b1017",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"231645514673025196327669108823980486706",
"7990384544805109744236812106735120194",
"104688841592412375850092821783487038875",
"66526571645010919539612101223632530943",
"268464125928449792427081351470959488407",
"334010739157675249115006055516902133311"
]
},
"deprecated": false,
"target": {
"file": "libr/anal/p/anal_6502.c"
}
}
]