4.3
CVSSv2

CVE-2018-18701

Published: 29/10/2018 Updated: 21/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu binutils 2.31

Vendor Advisories

Several security issues were fixed in libiberty ...
Several security issues were fixed in GNU binutils ...
An issue was discovered in cp-demanglec in GNU libiberty, as distributed in GNU Binutils 231 There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demanglec Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, ...