CVE-2016-4491
published 2017-02-24CVE-2016-4491: The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted…
medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and a buffer overflow, related to a node having "itself as ancestor more than once."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.28-3 (bookworm) | binutils 2.28-3 (bookworm) |
| debian | libiberty | < binutils 2.28-3 (bookworm) | binutils 2.28-3 (bookworm) |
| gnu | binutils | >= 0 < 2.28-3 | 2.28-3 |
| gnu | binutils | >= 0 < 2.28-3 | 2.28-3 |
| gnu | binutils | >= 0 < 2.28-3 | 2.28-3 |
| gnu | binutils | >= 0 < 2.28-3 | 2.28-3 |
| gnu | gdb | >= 0 < 7.7.1-0ubuntu5~14.04.3 | 7.7.1-0ubuntu5~14.04.3 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5 | 7.11.1-0ubuntu1~16.5 |
| valgrind | valgrind | >= 0 < 1:3.10.1-1ubuntu3~14.5 | 1:3.10.1-1ubuntu3~14.5 |
| valgrind | valgrind | >= 0 < 1:3.11.0-1ubuntu4.2 | 1:3.11.0-1ubuntu4.2 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.8HIGH