{"id":"CVE-2018-14015","details":"The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.","modified":"2026-08-07T14:54:17.898561Z","published":"2018-07-12T20:29:00.180Z","references":[{"type":"FIX","url":"https://github.com/radareorg/radare2/commit/d37d2b858ac47f2f108034be0bcecadaddfbc8b3"},{"type":"EVIDENCE","url":"https://github.com/radare/radare2/issues/10465"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2","events":[{"introduced":"d4ab235a7401612e80208e5cdf8c56a04713a587"},{"last_affected":"6e08e452a7ec231a73997c44b4ff556c2998c7d9"},{"fixed":"d37d2b858ac47f2f108034be0bcecadaddfbc8b3"}],"database_specific":{"cpe":"cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.7.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.7.0","2.6.9","2.6.0","2.5.0","2.4.0","2.2.0","2.1.0","2.0.1","2.0.0"],"database_specific":{"vanir_signatures_modified":"2026-08-07T14:54:17Z","vanir_signatures":[{"source":"https://github.com/radareorg/radare2/commit/d37d2b858ac47f2f108034be0bcecadaddfbc8b3","target":{"file":"libr/bin/dwarf.c","function":"r_bin_dwarf_parse_comp_unit"},"deprecated":false,"digest":{"function_hash":"14798236559159636232016039672416504645","length":1998},"id":"CVE-2018-14015-05052138","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/radareorg/radare2/commit/d37d2b858ac47f2f108034be0bcecadaddfbc8b3","target":{"file":"libr/bin/dwarf.c"},"deprecated":false,"digest":{"line_hashes":["38837014092717001301140362079195693660","311442303638115001835224331871286714378","148051777228907455241579188971409856646","144840294018848705629789983154616113291"],"threshold":0.9},"id":"CVE-2018-14015-5e460cf2","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14015.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}