First published: Thu Jul 12 2018(Updated: )
The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Radare2 | =2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14016 has been identified as a denial of service vulnerability.
To fix CVE-2018-14016, upgrade to radare2 version 2.7.1 or later.
CVE-2018-14016 is associated with remote denial of service attacks via crafted Mini Crash Dump files.
CVE-2018-14016 affects radare2 version 2.7.0.
CVE-2018-14016 can lead to a heap-based buffer over-read and cause the application to crash.