CVE-2016-4492
published 2017-02-24CVE-2016-4492: Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a…
PriorityP420medium4.4CVSS 3.0
AVLACLPRHUINSUCNINAH
EPSS
1.92%
77.7th percentile
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| debian | ht | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| debian | libiberty | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | gdb | >= 0 < 7.7.1-0ubuntu5~14.04.3 | 7.7.1-0ubuntu5~14.04.3 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5 | 7.11.1-0ubuntu1~16.5 |
| valgrind | valgrind | >= 0 < 1:3.10.1-1ubuntu3~14.5 | 1:3.10.1-1ubuntu3~14.5 |
| valgrind | valgrind | >= 0 < 1:3.11.0-1ubuntu4.2 | 1:3.11.0-1ubuntu4.2 |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5h9-4mvm-w8vm: Buffer overflow in the do_type function in cplus-dem
ghsa_unreviewed·2022-05-17
CVE-2016-4492 [MEDIUM] CWE-119 GHSA-v5h9-4mvm-w8vm: Buffer overflow in the do_type function in cplus-dem
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
OSV
gdb vulnerabilities
osv·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
gdb vulnerabilities
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It was discovered that gdb incorrectly handled certain string op
OSV
libiberty vulnerabilities
osv·2017-07-26·CVSS 7.8
CVE-2016-2226 [HIGH] libiberty vulnerabilities
libiberty vulnerabilities
It was discovered that libiberty incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2226)
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service. This issue only
applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2
OSV
valgrind vulnerabilities
osv·2017-06-21·CVSS 7.8
CVE-2016-2226 [HIGH] valgrind vulnerabilities
valgrind vulnerabilities
It was discovered that Valgrind incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS and Ubuntu 16.10. (CVE-2016-2226)
It was discovered that Valgrind incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
Valgrind to crash, resulting in a denial of service. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2016-4490, CVE-2016-4491, CVE-2016-4492,
CVE-2016-4493, CVE-2016-6131)
OSV
CVE-2016-4492: Buffer overflow in the do_type function in cplus-dem
osv·2017-02-24·CVSS 4.4
CVE-2016-4492 [MEDIUM] CVE-2016-4492: Buffer overflow in the do_type function in cplus-dem
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: Several security issues were fixed in gdb.
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It w
Ubuntu
libiberty vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.8
CVE-2016-2226 [HIGH] libiberty vulnerabilities
Title: libiberty vulnerabilities
Summary: Several security issues were fixed in libiberty.
It was discovered that libiberty incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2226)
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service. This issue only
applied to Ubuntu 14.04 LTS and Ubu
Ubuntu
Valgrind vulnerabilities
vendor_ubuntu·2017-06-21·CVSS 7.8
CVE-2016-2226 [HIGH] Valgrind vulnerabilities
Title: Valgrind vulnerabilities
Summary: Valgrind could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that Valgrind incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS and Ubuntu 16.10. (CVE-2016-2226)
It was discovered that Valgrind incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
Valgrind to crash, resulting in a denial of service. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2016-4490, CVE-2016-4491, CVE-2016-4
Red Hat
gcc: Read access violations
vendor_redhat·2016-05-03·CVSS 4.4
CVE-2016-4492 [MEDIUM] CWE-125 gcc: Read access violations
gcc: Read access violations
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils220 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-295 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-296 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-32 (Red Hat Enter
Debian
CVE-2016-4492: binutils - Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remot...
vendor_debian·2016·CVSS 4.4
CVE-2016-4492 [MEDIUM] CVE-2016-4492: binutils - Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remot...
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.20161102-1)
trixie: resolved (fixed in 2.27.51.20161102-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 mingw-gcc: various flaws [epel-all]
bugzilla·2016-05-05·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 mingw-gcc: various flaws [epel-all]
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 mingw-gcc: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
Bugzilla
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 msp430-gcc: various flaws [fedora-all]
bugzilla·2016-05-05·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 msp430-gcc: various flaws [fedora-all]
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 msp430-gcc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2016-4492 gcc: Read access violations
bugzilla·2016-05-05·CVSS 4.4
CVE-2016-4492 [MEDIUM] CVE-2016-4492 gcc: Read access violations
CVE-2016-4492 gcc: Read access violations
A vulnerability was found in gcc. A read access violation on source operand in the libiberty demangler causes its host applications to crash.
External references:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70926
Proposed patch:
https://gcc.gnu.org/ml/gcc-patches/2016-05/msg00223.html
Discussion:
Created msp430-gcc tracking bugs for this issue:
Affects: fedora-all [bug 1333388]
---
Created mingw-gcc tracking bugs for this issue:
Affects: epel-all [bug 1333389]
---
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/
http://www.openwall.com/lists/oss-security/2016/05/05/5http://www.securityfocus.com/bid/90014https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70926https://gcc.gnu.org/ml/gcc-patches/2016-05/msg00223.htmlhttp://www.openwall.com/lists/oss-security/2016/05/05/5http://www.securityfocus.com/bid/90014https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70926https://gcc.gnu.org/ml/gcc-patches/2016-05/msg00223.html
2017-02-24
Published