CVE-2018-18701
published 2018-10-29CVE-2018-18701: An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from…
PriorityP420medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.69%
74.6th percentile
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.32.51.20190707-1 (bookworm) | binutils 2.32.51.20190707-1 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2020-04-22
CVE-2018-1000876 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libiberty vulnerabilities
vendor_ubuntu·2020-04-08
CVE-2018-12641 libiberty vulnerabilities
Title: libiberty vulnerabilities
Summary: Several security issues were fixed in libiberty.
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
vendor_redhat·2018-10-21·CVSS 5.5
CVE-2018-18701 [MEDIUM] CWE-400 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
A vulnerability was found in GNU Binutils caused by excessive stack consumption in the cp-demangle.c file within GNU libiberty, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to stack exhaustion and causing the application to crash, resulting in a denial of servi
Debian
CVE-2018-18701: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
vendor_debian·2018·CVSS 5.5
CVE-2018-18701 [MEDIUM] CVE-2018-18701: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707-1)
trixie: resolved (fixed in 2.32.51.20190707-1)
GHSA
GHSA-8xqw-fxrf-xj63: An issue was discovered in cp-demangle
ghsa_unreviewed·2022-05-13
CVE-2018-18701 [MEDIUM] CWE-835 GHSA-8xqw-fxrf-xj63: An issue was discovered in cp-demangle
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
OSV
CVE-2018-18701: An issue was discovered in cp-demangle
osv·2018-10-29·CVSS 5.5
CVE-2018-18701 [MEDIUM] CVE-2018-18701: An issue was discovered in cp-demangle
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18701 [MEDIUM] CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file.
References:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87675
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1646530]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1646531]
---
Potentially a dupe of CVE-2018-18484, or at least the same root cause.
Bugzilla
CVE-2018-18701 mingw-binutils: binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c [epel-all]
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18701 [MEDIUM] CVE-2018-18701 mingw-binutils: binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c [epel-all]
CVE-2018-18701 mingw-binutils: binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c [fedora-all]
bugzilla·2018-11-05·CVSS 5.5
CVE-2018-18701 [MEDIUM] CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c [fedora-all]
CVE-2018-18701 binutils: infinite recursion in next_is_type_qual and cplus_demangle_type functions in cp-demangle.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2018-17794 binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
bugzilla·2018-10-02·CVSS 6.5
CVE-2018-17794 [MEDIUM] CVE-2018-17794 binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
CVE-2018-17794 binutils: NULL pointer dereference in libiberty/cplus-dem.c:work_stuff_copy_to_from() via crafted input
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
Upstream Bug:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87350
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1635083]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1635085]
Affects: fedora-all [bug 1635084]
---
Hi,
It looks like, below mentioned CVEs are related:
CVE-2018-18700
CVE-2018-18701
CVE-2018-17985
CVE-2018-17794
CVE-2018-18484
All of these CVEs redhat bugs are in open state (i.e. NEW
2018-10-29
Published