Back

HIGH

binutils: Integer overflow in cplus-dem.c:get_count() allows for denial of service

Published Oct 18, 2018

Description

The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string, as demonstrated by c++filt.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as moderate because an integer overflow in the get_count function in cplus-dem.c can lead to a denial of service or potentially other unintended behavior, achieving successful exploitation is not straightforward and depends on the specific conditions to craft input, which could trigger memory corruption.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 18, 2018
Updated Aug 5, 2024
Reserved Oct 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 17, 2017