CVE-2018-20673
04.01.2019, 18:29
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnu | binutils | 2.31.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| cpp |
| ||
| gcc |
| ||
| gcc-c |
| ||
| gcc-gdb-plugin |
| ||
| gcc-gfortran |
| ||
| gcc-offload-nvptx |
| ||
| gcc-plugin-devel |
| ||
| libasan |
| ||
| libatomic |
| ||
| libatomic-static |
| ||
| libgcc |
| ||
| libgfortran |
| ||
| libgomp |
| ||
| libgomp-offload-nvptx |
| ||
| libitm |
| ||
| libitm-devel |
| ||
| liblsan |
| ||
| libquadmath |
| ||
| libquadmath-devel |
| ||
| libstdc |
| ||
| libtsan |
| ||
| libubsan |
|