The rread* functions in libr/include/rendian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the rread_le32 function.
{ "urgency": "not yet assigned" }