{"id":"CVE-2017-6197","details":"The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function.","modified":"2026-07-08T11:36:02.767864Z","published":"2017-02-24T04:59:00.217Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96433"},{"type":"FIX","url":"https://github.com/radare/radare2/commit/1ea23bd6040441a21fbcfba69dce9a01af03f989"},{"type":"FIX","url":"https://github.com/radare/radare2/issues/6816"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"7482dee932d3e280c8adb66b1d8f08ca36148ed5"},{"last_affected":"7482dee932d3e280c8adb66b1d8f08ca36148ed5"},{"fixed":"1ea23bd6040441a21fbcfba69dce9a01af03f989"}],"database_specific":{"cpe":"cpe:2.3:a:radare:radare2:1.2.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.1"},{"last_affected":"1.2.1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6197.json","vanir_signatures_modified":"2026-07-08T11:36:02Z","vanir_signatures":[{"digest":{"function_hash":"17106255373911494429570082188668147584","length":179},"id":"CVE-2017-6197-3fa57bdd","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/1ea23bd6040441a21fbcfba69dce9a01af03f989","target":{"file":"libr/include/r_endian.h","function":"r_read_le16"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"56521480330843665188637392779150303898","length":251},"id":"CVE-2017-6197-4e5a4146","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/1ea23bd6040441a21fbcfba69dce9a01af03f989","target":{"file":"libr/include/r_endian.h","function":"r_read_le32"}},{"target":{"file":"libr/include/r_endian.h","function":"r_read_ble8"},"deprecated":false,"digest":{"length":85,"function_hash":"240859338887134180524976400952593795423"},"id":"CVE-2017-6197-6f574cc5","signature_type":"Function","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/1ea23bd6040441a21fbcfba69dce9a01af03f989"},{"id":"CVE-2017-6197-a12de820","signature_type":"Line","signature_version":"v1","source":"https://github.com/radareorg/radare2/commit/1ea23bd6040441a21fbcfba69dce9a01af03f989","target":{"file":"libr/include/r_endian.h"},"deprecated":false,"digest":{"line_hashes":["313675673046327587523446990894208781423","8331692281878784840840482341804180344","263550601277246970047494355983089374963","146563756917847262091650658945073759051","217108623745867226661246506362684292258","18509223722142561500624334448306012781","336038525693228917368063900097547061425","54284130475655386776894164122594373917","190852964013000928273541079107323887874","24541954589894186430689832511453273217","148124193760391448229734527852966329038","194942235687200741655068901152325387373","95291075085676708642323982430594718382","224066455727768564342716200064785388776","62692987984976974338590345141643360883","239662349361128358569316574690016566094","111458007510495800067370542414550465401","186393958106107312006630519142107882324","319996038801019187219635148015513028756","273162599114490560049332587369389200769","246897847062524815905566250040037422727","201762942505926023744383063878607172606","225060801306655685653232291442537413964","231098502893645925507813308872554597736","152509567359936682500041897132614881660","233558752094369697095014079520420126120","105627439455481981238877374350799895690","231371992082950537568399047232380630536","19062842662198554069237968113056886822"],"threshold":0.9}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}