cbcvebase.
CVE-2018-12698
published 2018-06-23

CVE-2018-12698: demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM)…

PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.69%
93.2th percentile
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianbinutils< binutils 2.32.51.20190707-1 (bookworm)binutils 2.32.51.20190707-1 (bookworm)
f5traffix_signaling_delivery_controller
f5traffix_signaling_delivery_controller5.0.0 – 5.1.0
gnubinutils
gnubinutils
gnubinutils>= 0 < 2.32.51.20190707-12.32.51.20190707-1
gnubinutils>= 0 < 2.32.51.20190707-12.32.51.20190707-1
gnubinutils>= 0 < 2.32.51.20190707-12.32.51.20190707-1
gnubinutils>= 0 < 2.32.51.20190707-12.32.51.20190707-1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.