PT-2018-2451 · Gnu+2 · Gnu Binutils+2
慕冬亮
·
Published
2018-03-02
·
Updated
2026-04-20
·
CVE-2018-9996
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.30
Description
The issue is related to stack exhaustion in the C++ demangling functions provided by libiberty, specifically in the demangle template value parm, demangle integral value, and demangle expression functions. This can lead to a denial of service.
Recommendations
For GNU Binutils version 2.30, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict the use of the demangling functions to minimize the risk of exploitation.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Gnu Binutils