CVE-2018-14015

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
12/07/2018
Last modified:
18/03/2025

Description

The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* 2.0.0 (including) 2.7.0 (including)