An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade binutils | Dec 27, 2019 | Mar 30, 2018 |
| Debian | — | Upgrade binutils | Jul 30, 2024 | Mar 30, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade binutilsUpgrade binutils-devel | Dec 4, 2019 | Mar 30, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade binutilsUpgrade binutils-devel | Dec 18, 2019 | Mar 30, 2018 |
| Oracle Solaris | — | Upgrade developer/gnu-binutils to version 2.32.0-11.4.9.0.1.1.0 on Solaris 11.4Upgrade developer/gnu-binutils-cross-sparc to version 2.32.0-11.4.9.0.1.1.0 on Solaris 11.4Upgrade developer/gnu-binutils-cross-i386 to version 2.32.0-11.4.9.0.1.1.0 on Solaris 11.4 | May 30, 2019 | Mar 30, 2018 |
| Ubuntu | — | Upgrade binutilsUpgrade binutils-multiarchUpgrade binutils-multiarch (Ubuntu Pro)Upgrade libiberty-devUpgrade binutils (Ubuntu Pro) | Apr 9, 2020 | Mar 30, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub