The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade htUpgrade binutilsUpgrade libiberty | Mar 31, 2017 | Jul 18, 2016 |
| Oracle Solaris | — | Upgrade developer/bcc to version 0.16.17-0.175.3.33.0.3.0 on Solaris 11.3Upgrade runtime/clisp to version 2.49-0.175.3.33.0.3.0 on Solaris 11.3Upgrade developer/gnu-binutils to version 2.30.1-0.175.3.33.0.3.0 on Solaris 11.3 | Jun 18, 2018 | Feb 7, 2017 |
| Suse | — | Upgrade valgrindUpgrade valgrind-develUpgrade valgrind-client-headers | Aug 9, 2024 | Feb 7, 2017 |
| Ubuntu | — | Upgrade binutils (Ubuntu Pro)Upgrade gdbUpgrade valgrindUpgrade libiberty-devUpgrade binutils-multiarch (Ubuntu Pro) | Jun 21, 2017 | Feb 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub