getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
References
Link | Resource |
---|---|
https://github.com/radare/radare2/commit/66191f780863ea8c66ace4040d0d04a8842e8432 | Patch Third Party Advisory |
https://github.com/radare/radare2/issues/12239 | Exploit Third Party Advisory |
https://github.com/radare/radare2/commit/66191f780863ea8c66ace4040d0d04a8842e8432 | Patch Third Party Advisory |
https://github.com/radare/radare2/issues/12239 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 03:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/radare/radare2/commit/66191f780863ea8c66ace4040d0d04a8842e8432 - Patch, Third Party Advisory | |
References | () https://github.com/radare/radare2/issues/12239 - Exploit, Third Party Advisory |
Information
Published : 2018-12-04 09:29
Updated : 2024-11-21 03:58
NVD link : CVE-2018-19842
Mitre link : CVE-2018-19842
CVE.ORG link : CVE-2018-19842
JSON object : View
Products Affected
radare
- radare2
CWE
CWE-125
Out-of-bounds Read