The rbinmdmpinitdirectory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.
[
{
"digest": {
"line_hashes": [
"231245728831905222921630915517020447311",
"70462949573779659726965858667787134888",
"316041451851517453610972412874365208476",
"264607919964460955081543941688388616685",
"309402496660179540303476061535278416151",
"282782220847829564334063846700709508954",
"206605873927010035432978506919036679103",
"485646185572423293497001910319109458",
"36108082595184941937583508015929792657",
"283211589649152713679052184031322531424",
"204520672791558034194382167091315669923",
"311599214643113986860321629278894842360",
"245033373197533747048034146955711637800",
"63553669983174285652154333237457904779",
"178346162769830567962157833645418877521",
"38250690214496304598030233344023414897"
],
"threshold": 0.9
},
"target": {
"file": "libr/bin/format/mdmp/mdmp.c"
},
"deprecated": false,
"id": "CVE-2018-14016-248d4a6c",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/eb7deb281df54771fb8ecf5890dc325a7d22d3e2",
"signature_type": "Line"
},
{
"digest": {
"length": 566.0,
"function_hash": "340205444792855952209826197946841515014"
},
"target": {
"file": "libr/bin/format/mdmp/mdmp.c",
"function": "r_bin_mdmp_init_directory"
},
"deprecated": false,
"id": "CVE-2018-14016-822cc878",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/eb7deb281df54771fb8ecf5890dc325a7d22d3e2",
"signature_type": "Function"
}
]