PT-2019-10156 · Gnu+6 · Gnu Binutils+6

Tfx

·

Published

2018-12-27

·

Updated

2026-04-20

·

CVE-2018-20673

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.31.1
Description: The demangle template function in cplus-dem.c contains an integer overflow vulnerability that can trigger a heap-based buffer overflow. This issue is demonstrated by the nm tool.
Recommendations: For GNU Binutils version 2.31.1, consider updating to a newer version that contains a fix for this issue, as using the demangle template function can lead to a heap-based buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4386
ALT-PU-2019-3046
AZL-41601
CESA-2021_4386
CVE-2018-20673
ECHO-4D86-022A-58EE
RHSA-2021:4386
RHSA-2021_4386
RLSA-2021:4386

Affected Products

Alt Linux
Almalinux
Centos
Debian
Gnu Binutils
Red Hat
Rocky Linux