Back

MEDIUM

binutils: stack consumption in function d_count_templates_scopes in cp-demangle.c

Published Feb 24, 2019

Description

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls.

Affected products

Remediation

Red Hat statement

The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The buffer overflow in d_expression_1() only triggers during the parsing of malformed ELF files, which would require an attacker to convince a user to process a malicious ELF file with readelf. Moreover, binutils does not handle privileged operations, meaning exploitation is unlikely to lead to system compromise or escalation of privileges. Additionally, the impact is localized to the application itself, without affecting the broader system or network security.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 24, 2019
Updated Aug 4, 2024
Reserved Feb 23, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 18, 2019