Back

MEDIUM

binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c

Published Oct 27, 2018

Description

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions d_name(), d_encoding(), and d_local_name() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.

Affected products

Remediation

Red Hat statement

Red Hat has determined this flaw to be of low impact as successful exploitation results in a crash (denial of service) of the application utilizing the binutils library and does not impact system-wide stability or lead to arbitrary code execution or memory corruption.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 27, 2018
Updated Aug 5, 2024
Reserved Oct 27, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 22, 2018