Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46195

Опубликовано: 29 янв. 2021
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash.

Отчет

This flaw has been rated as having a security impact of Low. The problem is only triggered when deliberately corrupt input is passed to a tool that attempts to demangle symbol names. Normal users should never encounter this problem.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-gcc-295Out of support scope
Red Hat Enterprise Linux 6compat-gcc-296Out of support scope
Red Hat Enterprise Linux 6compat-gcc-32Out of support scope
Red Hat Enterprise Linux 6compat-gcc-34Out of support scope
Red Hat Enterprise Linux 6gccOut of support scope
Red Hat Enterprise Linux 7compat-gcc-32Out of support scope
Red Hat Enterprise Linux 7compat-gcc-34Out of support scope
Red Hat Enterprise Linux 7compat-gcc-44Out of support scope
Red Hat Enterprise Linux 7gccOut of support scope
Red Hat Enterprise Linux 8gccNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2046300gcc: uncontrolled recursion in libiberty/rust-demangle.c

EPSS

Процентиль: 49%
0.00259
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

CVSS3: 5.5
nvd
больше 3 лет назад

GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

CVSS3: 5.5
debian
больше 3 лет назад

GCC v12.0 was discovered to contain an uncontrolled recursion via the ...

github
больше 3 лет назад

GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

oracle-oval
почти 3 года назад

ELSA-2022-8415: mingw-gcc security and bug fix update (LOW)

EPSS

Процентиль: 49%
0.00259
Низкий

3.3 Low

CVSS3