{"id":"CVE-2017-15368","details":"The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_bin2str call.","modified":"2026-08-07T14:49:36.868054Z","published":"2017-10-16T01:29:01.030Z","references":[{"type":"FIX","url":"https://github.com/radare/radare2/commit/52b1526443c1f433087928291d1c3d37a5600515"},{"type":"FIX","url":"https://github.com/radare/radare2/issues/8673"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"d4ab235a7401612e80208e5cdf8c56a04713a587"},{"last_affected":"d4ab235a7401612e80208e5cdf8c56a04713a587"},{"fixed":"52b1526443c1f433087928291d1c3d37a5600515"}],"database_specific":{"cpe":"cpe:2.3:a:radare:radare2:2.0.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.0.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15368.json","vanir_signatures_modified":"2026-08-07T14:49:36Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"220973872098731940812092874540402311170","length":8944},"id":"CVE-2017-15368-0bd237f3","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/52b1526443c1f433087928291d1c3d37a5600515","target":{"file":"libr/asm/arch/wasm/wasm.c","function":"wasm_dis"}},{"source":"https://github.com/radareorg/radare2/commit/52b1526443c1f433087928291d1c3d37a5600515","target":{"file":"libr/asm/arch/wasm/wasm.c"},"deprecated":false,"digest":{"line_hashes":["264992558448024667854249177351062730901","333437584711275879921249801947901073891","190826572119966711749169165895605270774","114233611036187745318326970545029509349","42073040184298198897620049621078341959","181092958784557052559707139485284959272","329092736694650349859053289205199862615","213117915042792317916694154683355287783","329777032915206919193173388803592916135","74924640570297500604480964461276825573","22655722049319263921495072085600989198","31116586002094253221260480378756839046","302904642283406408172131007475488142198","43587005996764303487955361185369441174","126241374497284361037396170545756530154","9267414059130277964538738099062741723","254846897502635673712391654099710030653","330523957279119370271402730400897249420","289757265379566316237616801862019256728","173859399597882282154978915592156315904","251573502438275019381361271843147405376","118540288796176528195953084196175092561","108711163085664935651869682536057843086","212511558419246659020814486924840867793","243927298559685498776389528001194428610","307659664363274250767379498754760745886","73823874787572897330743414190526071010","241684039061993393448047512187792782052","201763234123213232226574511313452922510","255885969774870139124257216155955713231"],"threshold":0.9},"id":"CVE-2017-15368-7eab9e68","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}