CVE-2018-18484
published 2018-10-18CVE-2018-18484: An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions…
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.88%
77.3th percentile
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.32.51.20190707-1 (bookworm) | binutils 2.32.51.20190707-1 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2020-04-22
CVE-2018-1000876 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libiberty vulnerabilities
vendor_ubuntu·2020-04-08
CVE-2018-12641 libiberty vulnerabilities
Title: libiberty vulnerabilities
Summary: Several security issues were fixed in libiberty.
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: Stack exhaustion in cp-demangle.c allows for denial of service
vendor_redhat·2018-10-17·CVSS 5.5
CVE-2018-18484 [MEDIUM] CWE-400 binutils: Stack exhaustion in cp-demangle.c allows for denial of service
binutils: Stack exhaustion in cp-demangle.c allows for denial of service
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
Statement: Red Hat has determined this vulnerability is of low impact as the result of successful exploitation is a crash in the application utilizing libiberty's cp-demangler. There is no direct risk of code execution, privilege escalation, or system-wide instability.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils220 (Red Hat Enterprise Linux 5) - Not affected
Package: binuti
Debian
CVE-2018-18484: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
vendor_debian·2018·CVSS 5.5
CVE-2018-18484 [MEDIUM] CVE-2018-18484: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707-1)
trixie: resolved (fixed in 2.32.51.20190707-1)
GHSA
GHSA-cc39-h55x-vp6h: An issue was discovered in cp-demangle
ghsa_unreviewed·2022-05-13
CVE-2018-18484 [MEDIUM] CWE-674 GHSA-cc39-h55x-vp6h: An issue was discovered in cp-demangle
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
OSV
CVE-2018-18484: An issue was discovered in cp-demangle
osv·2018-10-18·CVSS 5.5
CVE-2018-18484 [MEDIUM] CVE-2018-18484: An issue was discovered in cp-demangle
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18484 binutils: Stack exhaustion in cp-demangle.c allows for denial of service [fedora-all]
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18484 [MEDIUM] CVE-2018-18484 binutils: Stack exhaustion in cp-demangle.c allows for denial of service [fedora-all]
CVE-2018-18484 binutils: Stack exhaustion in cp-demangle.c allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2018-18484 binutils: Stack exhaustion in cp-demangle.c allows for denial of service
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18484 [MEDIUM] CVE-2018-18484 binutils: Stack exhaustion in cp-demangle.c allows for denial of service
CVE-2018-18484 binutils: Stack exhaustion in cp-demangle.c allows for denial of service
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_function_type, d_function_type.
Upstream Bugs:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87636
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1645962]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1645964]
---
Reproduces consistently on RHEL.
---
So, this "flaw" seem to be duplicated many times upstream. See: https://gcc.gnu.org/bugzilla/show_bug.c
Bugzilla
CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18701 [MEDIUM] CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file.
References:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87675
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1646530]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1646531]
---
Potentially a dupe of CVE-2018-18484, or at least the same root cause.
Bugzilla
CVE-2018-18700 binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18700 [MEDIUM] CVE-2018-18700 binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c
CVE-2018-18700 binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions d_name(), d_encoding(), and d_local_name() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file.
References:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87681
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1646536]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1646537]
---
Potentially a dupe of CVE-2018-18484, or at least the same root cause.
Bugzilla
CVE-2018-18484 mingw-binutils: binutils: Stack exhaustion in cp-demangle.c allows for denial of service [epel-all]
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18484 [MEDIUM] CVE-2018-18484 mingw-binutils: binutils: Stack exhaustion in cp-demangle.c allows for denial of service [epel-all]
CVE-2018-18484 mingw-binutils: binutils: Stack exhaustion in cp-demangle.c allows for denial of service [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-17794 binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
bugzilla·2018-10-02·CVSS 6.5
CVE-2018-17794 [MEDIUM] CVE-2018-17794 binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
CVE-2018-17794 binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
Upstream Bug:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87350
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1635083]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1635085]
Affects: fedora-all [bug 1635084]
---
Hi,
It looks like, below mentioned CVEs are related:
CVE-2018-18700
CVE-2018-18701
CVE-2018-17985
CVE-2018-17794
CVE-2018-18484
All of these CVEs redhat bugs are in open state (i.e. NEW
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.htmlhttp://www.securityfocus.com/bid/105693https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87636https://usn.ubuntu.com/4326-1/https://usn.ubuntu.com/4336-1/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.htmlhttp://www.securityfocus.com/bid/105693https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87636https://usn.ubuntu.com/4326-1/https://usn.ubuntu.com/4336-1/
2018-10-18
Published