The getdebuginfo() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.
[
{
"signature_type": "Line",
"id": "CVE-2018-11379-239717b8",
"digest": {
"line_hashes": [
"195342921626668978905769797848564384085",
"299597133818556324622741801796026882732",
"146360435971586705765915970075424593476",
"253011028945088115769697052480343597160",
"118676659225823661518027985482366259852",
"267021491414392724615190134162672645453",
"201236357109002593463181426344354295805",
"301597490813403662632511272824089441371",
"205956667256020520492458202986329257172",
"397071036691459829424013577574892142",
"182298217996095470119496356060637767602",
"323605138358458446330969518010958749079",
"214856859076998003940568257498302910684",
"111881495015248821593256516672388929562",
"249278781363752697501216326800732786212"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://github.com/radareorg/radare2/commit/4e1cf0d3e6f6fe2552a269def0af1cd2403e266c",
"target": {
"file": "libr/bin/format/pe/pe.c"
},
"signature_version": "v1"
},
{
"signature_type": "Function",
"id": "CVE-2018-11379-47683404",
"digest": {
"function_hash": "291917089660934115897274696791522513554",
"length": 195.0
},
"deprecated": false,
"source": "https://github.com/radareorg/radare2/commit/4e1cf0d3e6f6fe2552a269def0af1cd2403e266c",
"target": {
"file": "libr/bin/format/pe/pe.c",
"function": "get_nb10"
},
"signature_version": "v1"
}
]