In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asmx86nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "3.1.1"
},
{
"fixed": "3.1.1"
}
],
"vendor_product": "radare:radare2"
}
]
}