Back

MEDIUM

binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input

Published Sep 30, 2018

Description

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

Affected products

Remediation

Red Hat statement

This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this NULL pointer dereference is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with c++filt. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 30, 2018
Updated Aug 5, 2024
Reserved Sep 30, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 2, 2018
ENISA EUVD
Assigner mitre
Published Sep 30, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-9540