CVE-2018-20657
published 2019-01-02CVE-2018-20657: The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.04%
89.5th percentile
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | traffix_signaling_delivery_controller | — | — |
| f5 | traffix_signaling_delivery_controller | 5.0.0 – 5.1.0 | — |
| gnu | binutils | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qhfg-hc2h-mmfc: The demangle_template function in cplus-dem
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2018-20657 [HIGH] CWE-772 GHSA-qhfg-hc2h-mmfc: The demangle_template function in cplus-dem
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
OSV
CVE-2018-20657: The demangle_template function in cplus-dem
osv·2019-01-02·CVSS 7.5
CVE-2018-20657 [HIGH] CVE-2018-20657: The demangle_template function in cplus-dem
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
Red Hat
libiberty: Memory leak in demangle_template function resulting in a denial of service
vendor_redhat·2018-12-18·CVSS 7.5
CVE-2018-20657 [HIGH] CWE-400 libiberty: Memory leak in demangle_template function resulting in a denial of service
libiberty: Memory leak in demangle_template function resulting in a denial of service
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
A vulnerability was found in the demangle_template function in GNU libiberty, as distributed in GNU Binutils, where a memory leak could occur, a specially crafted file could cause the application to consume excessive memory, potentially leading to a crash.
Statement: This vulnerability is rated as low severity because it results in a memory leak that can cause the application to crash, it may impact performance, it does not pose a significant risk
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2018-20657 libiberty: Memory leak in demangle_template function resulting in a denial of service
bugzilla·2019-01-09·CVSS 7.5
CVE-2018-20657 [HIGH] CVE-2018-20657 libiberty: Memory leak in demangle_template function resulting in a denial of service
CVE-2018-20657 libiberty: Memory leak in demangle_template function resulting in a denial of service
A memory leak was found in the demangle_template function in GNU libiberty, as distributed in GNU Binutils. A crafted filed could cause the application to crash.
Upstream issue:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1664713]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1664715]
Affects: fedora-all [bug 1664714]
---
`work->tmpl_argvec` is allocated but never freed in demangle_template() function.
---
10 bytes hard-to-reach memory leak which only possibly impacts short-lived programs.
I believe that a reproducer would be even harder to do with binutils,
http://www.securityfocus.com/bid/106444https://access.redhat.com/errata/RHSA-2019:3352https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539https://support.f5.com/csp/article/K62602089http://www.securityfocus.com/bid/106444https://access.redhat.com/errata/RHSA-2019:3352https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539https://support.f5.com/csp/article/K62602089
2019-01-02
Published