getToken in libr/asm/p/asmx86nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
[
{
"source": "https://github.com/radareorg/radare2/commit/66191f780863ea8c66ace4040d0d04a8842e8432",
"id": "CVE-2018-19842-05c1c3e4",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libr/asm/p/asm_x86_nz.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"17289356862643552779117616738638230764",
"218863782527369619721098549656350751255",
"290320381442572029114878873901956750113",
"297897495203835988794858844677240805684",
"177271434313444291677729203373867461009",
"35651211959063986914497847455555591644",
"80975977767538660953709823931627412248",
"313607390506123454966458181526683900340",
"289432130671053739689270343446895357773",
"191636119298625527863592410983501793028",
"22809562492750362425439120063100732326",
"58660093387601925117607657048549441976",
"215235810792463894212391932677201206971",
"297697175989800728676707968863080534874",
"120708633053791330654917401913261671029",
"88629528405458015762772855361877408566",
"241086510162143667321637698022623388458"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/radareorg/radare2/commit/66191f780863ea8c66ace4040d0d04a8842e8432",
"id": "CVE-2018-19842-22a0d70d",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "getToken",
"file": "libr/asm/p/asm_x86_nz.c"
},
"digest": {
"length": 634.0,
"function_hash": "137780432575582775683134105875768059340"
},
"signature_type": "Function"
}
]