An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade binutils | Dec 27, 2019 | Mar 30, 2018 |
| Debian | — | Upgrade binutils | Jul 30, 2024 | Mar 30, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade binutils-develUpgrade binutils | Dec 4, 2019 | Mar 30, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade binutilsUpgrade binutils-devel | Dec 18, 2019 | Mar 30, 2018 |
| Oracle Solaris | — | Upgrade developer/gnu-binutils-cross-i386 to version 2.32.0-11.4.9.0.1.1.0 on Solaris 11.4Upgrade developer/gnu-binutils-cross-sparc to version 2.32.0-11.4.9.0.1.1.0 on Solaris 11.4Upgrade developer/gnu-binutils to version 2.32.0-11.4.9.0.1.1.0 on Solaris 11.4 | May 30, 2019 | Mar 30, 2018 |
| Ubuntu | — | Upgrade binutilsUpgrade binutils-multiarch (Ubuntu Pro)Upgrade binutils-multiarchUpgrade libiberty-devUpgrade binutils (Ubuntu Pro) | Apr 9, 2020 | Mar 30, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub