CVE-2018-20673
published 2019-01-04CVE-2018-20673: The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create…
PriorityP422medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.64%
74.7th percentile
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libiberty: Integer overflow in demangle_template() function
vendor_redhat·2018-12-27·CVSS 5.5
CVE-2018-20673 [MEDIUM] CWE-190 libiberty: Integer overflow in demangle_template() function
libiberty: Integer overflow in demangle_template() function
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Statement: This issue did not affect the versions of gdb as shipped with Red Hat Enterprise Linux 7 and with Red Hat Developer Toolset 7 and 8 as they are compiled only for 64bit architectures, where the flaw is not present.
This vulnerability has been rated as Low severity for Red Hat Enterprise Linux 8, as the circumstances to exploit are particularly unlikely. A crafted binary file must be passed to one of the affected tools, in a 32-bit environment,
Debian
CVE-2018-20673: binutils - The demangle_template function in cplus-dem.c in GNU libiberty, as distributed i...
vendor_debian·2018·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673: binutils - The demangle_template function in cplus-dem.c in GNU libiberty, as distributed i...
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-jx5v-cp2v-88f2: The demangle_template function in cplus-dem
ghsa_unreviewed·2022-05-13
CVE-2018-20673 [MEDIUM] CWE-787 GHSA-jx5v-cp2v-88f2: The demangle_template function in cplus-dem
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
OSV
CVE-2018-20673: The demangle_template function in cplus-dem
osv·2019-01-04·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673: The demangle_template function in cplus-dem
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20673 avr-binutils: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 avr-binutils: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 avr-binutils: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2018-20673 gcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 gcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 gcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2018-20673 gccxml: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 gccxml: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 gccxml: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-20673 gdb: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 gdb: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 gdb: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2018-20673 sdcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 sdcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 sdcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2018-20673 gputils: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 gputils: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 gputils: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-20673 avr-gcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
bugzilla·2019-01-14·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 avr-gcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
CVE-2018-20673 avr-gcc: libiberty: Integer overflow in demangle_template() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-20673 libiberty: Integer overflow in demangle_template() function
bugzilla·2019-01-09·CVSS 5.5
CVE-2018-20673 [MEDIUM] CVE-2018-20673 libiberty: Integer overflow in demangle_template() function
CVE-2018-20673 libiberty: Integer overflow in demangle_template() function
An integer overflow was found in demangle_template() function in GNU libiberty. A crafted file could cause the application to crash.
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=24039
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1664713]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1664715]
Affects: fedora-all [bug 1664714]
---
Upstream issue was moved to gcc project:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88783
---
libiberty is embedded in at least gcc, gdb and binutils.
---
Created avr-binutils tracking bugs for this issue:
Affects: fedora-all [bug 1665957]
Created avr-gcc tracking bugs for this issue:
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
2019-01-04
Published