CVE-2018-12698 Information
Feb 14, 2021
cve
Description
demangle_template in cplus-dem.c in GNU libiberty as distributed in GNU Binutils 2.30 allows attackers to trigger excessive memory consumption (aka OOM) during the \Create an array for saving the template argument values\ XNEWVEC call. This can occur during execution of objdump.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://www.securityfocus.com/bid/104539 https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102 https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454 https://security.gentoo.org/glsa/201908-01 https://sourceware.org/bugzilla/show_bug.cgi?id=23057 https://usn.ubuntu.com/4326-1/ https://usn.ubuntu.com/4336-1/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: