CVE-2018-18700

Source
https://cve.org/CVERecord?id=CVE-2018-18700
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18700.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-18700
Downstream
Published
2018-10-29T12:29:04.710Z
Modified
2026-07-08T17:16:56.012655Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions dname(), dencoding(), and dlocalname() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.

References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Introduced
af127c216949509e57ab2a28cc56c44e4e548813
Last affected
af127c216949509e57ab2a28cc56c44e4e548813
Database specific
{
    "cpe": "cpe:2.3:a:gnu:binutils:2.31:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "2.31"
        },
        {
            "last_affected": "2.31"
        }
    ]
}

Affected versions

2.*
2.31
Other
binutils-2_31

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18700.json"