binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
Published Sep 30, 2018
6.5
MEDIUMCVSS 3.0
EPSS 1.87%
Description
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
binutils
Will not fix
Red Hat Enterprise Linux 5
binutils220
Not affected
Red Hat Enterprise Linux 6
binutils
Will not fix
Red Hat Enterprise Linux 7
binutils
Will not fix
Red Hat Enterprise Linux 8
binutils
Will not fix
Red Hat Enterprise Linux 8
mingw-binutils
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | binutils220 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this NULL pointer dereference is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with c++filt. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.
References (8)
- https://access.redhat.com/security/cve/CVE-2018-17794 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1635082 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-9540 Advisory
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87350 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-17794
- https://usn.ubuntu.com/4326-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4336-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-17794
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-17794 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1635082 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-9540 | Advisory | |
| https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87350 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-17794 | ||
| https://usn.ubuntu.com/4326-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://usn.ubuntu.com/4336-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2018-17794 |
Change history (0)
No recorded changes yet.