Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12698

Опубликовано: 23 июн. 2018
Источник: debian
EPSS Низкий

Описание

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
binutilsfixed2.32.51.20190707-1package

Примечания

  • https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454

  • https://sourceware.org/bugzilla/show_bug.cgi?id=23057

  • Fixed by: https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=03e51746ed98d9106803f6009ebd71ea670ad3b9

  • binutils not covered by security support

EPSS

Процентиль: 83%
0.01892
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

CVSS3: 3.3
redhat
почти 8 лет назад

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

CVSS3: 7.5
nvd
больше 7 лет назад

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

CVSS3: 7.5
github
больше 3 лет назад

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

CVSS3: 7.5
fstec
почти 8 лет назад

Уязвимость функции demangle_template компонента cplus-dem.c программного средства разработки GNU Binutils, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.01892
Низкий