CVE-2016-6131
published 2017-02-07CVE-2016-6131: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.62%
90.7th percentile
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| debian | ht | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| debian | libiberty | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | gdb | >= 0 < 7.7.1-0ubuntu5~14.04.3 | 7.7.1-0ubuntu5~14.04.3 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5 | 7.11.1-0ubuntu1~16.5 |
| valgrind | valgrind | >= 0 < 1:3.10.1-1ubuntu3~14.5 | 1:3.10.1-1ubuntu3~14.5 |
| valgrind | valgrind | >= 0 < 1:3.11.0-1ubuntu4.2 | 1:3.11.0-1ubuntu4.2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j4gc-wrx5-3h2g: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe
ghsa_unreviewed·2022-05-17
CVE-2016-6131 [HIGH] CWE-20 GHSA-j4gc-wrx5-3h2g: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
OSV
gdb vulnerabilities
osv·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
gdb vulnerabilities
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It was discovered that gdb incorrectly handled certain string op
OSV
libiberty vulnerabilities
osv·2017-07-26·CVSS 7.8
CVE-2016-2226 [HIGH] libiberty vulnerabilities
libiberty vulnerabilities
It was discovered that libiberty incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2226)
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service. This issue only
applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2
OSV
valgrind vulnerabilities
osv·2017-06-21·CVSS 7.8
CVE-2016-2226 [HIGH] valgrind vulnerabilities
valgrind vulnerabilities
It was discovered that Valgrind incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS and Ubuntu 16.10. (CVE-2016-2226)
It was discovered that Valgrind incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
Valgrind to crash, resulting in a denial of service. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2016-4490, CVE-2016-4491, CVE-2016-4492,
CVE-2016-4493, CVE-2016-6131)
OSV
CVE-2016-6131: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe
osv·2017-02-07·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: Several security issues were fixed in gdb.
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It w
Ubuntu
libiberty vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.8
CVE-2016-2226 [HIGH] libiberty vulnerabilities
Title: libiberty vulnerabilities
Summary: Several security issues were fixed in libiberty.
It was discovered that libiberty incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2226)
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service. This issue only
applied to Ubuntu 14.04 LTS and Ubu
Ubuntu
Valgrind vulnerabilities
vendor_ubuntu·2017-06-21·CVSS 7.8
CVE-2016-2226 [HIGH] Valgrind vulnerabilities
Title: Valgrind vulnerabilities
Summary: Valgrind could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that Valgrind incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS and Ubuntu 16.10. (CVE-2016-2226)
It was discovered that Valgrind incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
Valgrind to crash, resulting in a denial of service. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2016-4490, CVE-2016-4491, CVE-2016-4
Red Hat
gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler
vendor_redhat·2016-06-29·CVSS 7.5
CVE-2016-6131 [HIGH] CWE-674 gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler
gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
Statement: Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.
Package: binutils (Red Hat Enterprise Linux 5) - Not affected
Package: compat-gcc-295 (Red Hat Enterprise Linux 5) - Not affected
Package: compat-gcc-296 (Red Hat Enterprise Linux 5) - Not affected
Package: compat-gcc-32 (Red Hat Enterprise Linux 5) - Not affected
Package: compat-gcc-34 (Red Hat Enterprise Linux 5) - Not affected
Package: gcc (Red Hat Enterprise Linux 5) - Not affected
Pac
Debian
CVE-2016-6131: binutils - The demangler in GNU Libiberty allows remote attackers to cause a denial of serv...
vendor_debian·2016·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131: binutils - The demangler in GNU Libiberty allows remote attackers to cause a denial of serv...
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.20161102-1)
trixie: resolved (fixed in 2.27.51.20161102-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6131 gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-6131 binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]
CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-6131 gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler
CVE-2016-6131 gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler
A stack overflow vulnerability in the libiberty demangler was found, which causes its host application to crash on a tainted branch instruction. The problem is caused by a self-reference in a mangled type string that is "remembered" for later reference. This leads to an infinite recursion during the demangling.
Upstream bug:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=71696
Proposed patch:
https://gcc.gnu.org/ml/gcc-patches/2016-06/msg02030.html
CVE assignment:
http://seclists.org/oss-sec/2016/q2/633
Discussion:
Created gcc tracking bugs for this issue:
Affects: fedora-all [bug 1352076]
---
Created mingw-gdb tracking bugs for this issue:
Affects: fedora-all [bug 1352074]
Affects: epel-7
Bugzilla
CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]
CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-7]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-7]
CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically
Bugzilla
CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2016-6131 compat-gcc-296: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 compat-gcc-296: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 compat-gcc-296: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2016-6131 gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-6131 compat-gcc-32: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 compat-gcc-32: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 compat-gcc-32: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2016-6131 compat-gcc-34: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-6131 [HIGH] CVE-2016-6131 compat-gcc-34: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
CVE-2016-6131 compat-gcc-34: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
http://www.openwall.com/lists/oss-security/2016/06/30/4http://www.openwall.com/lists/oss-security/2016/06/30/7http://www.securityfocus.com/bid/91519https://gcc.gnu.org/bugzilla/show_bug.cgi?id=71696https://gcc.gnu.org/ml/gcc-patches/2016-06/msg02030.htmlhttp://www.openwall.com/lists/oss-security/2016/06/30/4http://www.openwall.com/lists/oss-security/2016/06/30/7http://www.securityfocus.com/bid/91519https://gcc.gnu.org/bugzilla/show_bug.cgi?id=71696https://gcc.gnu.org/ml/gcc-patches/2016-06/msg02030.html
2017-02-07
Published