In radare 2.0.1, an out-of-bounds read vulnerability exists in stringscanrange() in libr/bin/bin.c when doing a string search.
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"226300123692389878708072809038383876128",
"192663042669872138206132487810001732809",
"323094720443130918405205879046071326102",
"120100809523800864891341131033169388190",
"241363127384712706210041893466377221585",
"182530849118491708037063695165835487159",
"164196666576526976756570463295443729943",
"133723766236519775928582904467866297444",
"165454809221906479215757330847061691495",
"185556006068249334778324797798655698931",
"136589352575399249727385850433943354976",
"232703428829618010722858712448320778067",
"14585748013220834343756543672312303398"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/radareorg/radare2/commit/d31c4d3cbdbe01ea3ded16a584de94149ecd31d9",
"signature_version": "v1",
"target": {
"file": "libr/bin/bin.c"
},
"id": "CVE-2017-16358-6aaed27a"
},
{
"deprecated": false,
"digest": {
"length": 2855.0,
"function_hash": "61988472564367060628925422415457327633"
},
"signature_type": "Function",
"source": "https://github.com/radareorg/radare2/commit/d31c4d3cbdbe01ea3ded16a584de94149ecd31d9",
"signature_version": "v1",
"target": {
"function": "string_scan_range",
"file": "libr/bin/bin.c"
},
"id": "CVE-2017-16358-f3d774c9"
}
]