CVE-2016-6131Improper Input Validation in Binutils

Severity
7.5HIGHNVD
EPSS
1.8%
top 17.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 7
Latest updateMay 17

Description

The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

Debiangnu/binutils< 2.27.51.20161102-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j4gc-wrx5-3h2g: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe2022-05-17
OSV
CVE-2016-6131: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe2017-02-07
CVEList
CVE-2016-6131: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe2017-02-07

📋Vendor Advisories

6
Ubuntu
GNU binutils vulnerabilities2021-07-21
Ubuntu
gdb vulnerabilities2017-07-26
Ubuntu
libiberty vulnerabilities2017-07-26
Ubuntu
Valgrind vulnerabilities2017-06-21
Red Hat
gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler2016-06-29

💬Community

13
Bugzilla
CVE-2016-6131 gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]2016-07-01
Bugzilla
CVE-2016-6131 binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]2016-07-01
Bugzilla
CVE-2016-6131 mingw-binutils: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]2016-07-01
Bugzilla
CVE-2016-6131 mingw-gdb: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [fedora-all]2016-07-01
Bugzilla
CVE-2016-6131 mingw-gcc: gcc,gdb,binutils,libitm: Stack overflow vulnerability in libiberty demangler [epel-all]2016-07-01
CVE-2016-6131 — Improper Input Validation in Binutils | cvebase