{"id":"CVE-2018-14015","details":"The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.","modified":"2026-04-11T12:27:23.678182Z","published":"2018-07-12T20:29:00.180Z","references":[{"type":"FIX","url":"https://github.com/radareorg/radare2/commit/d37d2b858ac47f2f108034be0bcecadaddfbc8b3"},{"type":"EVIDENCE","url":"https://github.com/radare/radare2/issues/10465"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radare/radare2","events":[{"introduced":"d4ab235a7401612e80208e5cdf8c56a04713a587"},{"last_affected":"6e08e452a7ec231a73997c44b4ff556c2998c7d9"}],"database_specific":{"versions":[{"introduced":"2.0.0"},{"last_affected":"2.7.0"}]}},{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"0"},{"fixed":"d37d2b858ac47f2f108034be0bcecadaddfbc8b3"}]}],"versions":["0.10.0","0.10.1","0.10.2","0.10.3","0.10.4","0.10.4-termux4","0.10.5","0.10.6","0.8.6","0.8.8","0.9","0.9.2","0.9.4","0.9.6","0.9.7","0.9.8","0.9.8-rc1","0.9.8-rc2","0.9.8-rc3","0.9.8-rc4","0.9.9","1.0","1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.2.0-git","1.3.0","1.3.0-git","1.4.0","1.5.0","1.6.0","2.0.0","2.0.1","2.1.0","2.2.0","2.4.0","2.5.0","2.6.0","2.6.9","2.7.0","radare2-windows-nightly","termux"],"database_specific":{"vanir_signatures_modified":"2026-04-11T12:27:23Z","vanir_signatures":[{"target":{"file":"libr/bin/dwarf.c","function":"r_bin_dwarf_parse_comp_unit"},"signature_type":"Function","digest":{"length":1998,"function_hash":"14798236559159636232016039672416504645"},"deprecated":false,"signature_version":"v1","id":"CVE-2018-14015-05052138","source":"https://github.com/radareorg/radare2/commit/d37d2b858ac47f2f108034be0bcecadaddfbc8b3"},{"target":{"file":"libr/bin/dwarf.c"},"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["38837014092717001301140362079195693660","311442303638115001835224331871286714378","148051777228907455241579188971409856646","144840294018848705629789983154616113291"]},"deprecated":false,"signature_version":"v1","id":"CVE-2018-14015-5e460cf2","source":"https://github.com/radareorg/radare2/commit/d37d2b858ac47f2f108034be0bcecadaddfbc8b3"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14015.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}