CVE-2018-20460

In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:01

Type Values Removed Values Added
References () https://github.com/radare/radare2/commit/df167c7db545953bb7f71c72e98e7a3ca0c793bf - Patch, Third Party Advisory () https://github.com/radare/radare2/commit/df167c7db545953bb7f71c72e98e7a3ca0c793bf - Patch, Third Party Advisory
References () https://github.com/radare/radare2/issues/12376 - Exploit, Third Party Advisory () https://github.com/radare/radare2/issues/12376 - Exploit, Third Party Advisory

Information

Published : 2018-12-25 19:29

Updated : 2024-11-21 04:01


NVD link : CVE-2018-20460

Mitre link : CVE-2018-20460

CVE.ORG link : CVE-2018-20460


JSON object : View

Products Affected

radare

  • radare2
CWE
CWE-787

Out-of-bounds Write