CVE-2016-4491: Buffer Overflow
Last updated 24 July 2024
Other sources
The dprintcomp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and a buffer overflow, related to a node having "itself as ancestor more than once."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-4491?
CVE-2016-4491 is a vulnerability in the d_print_comp function in cp-demangle.c in libiberty that allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
How does CVE-2016-4491 work?
CVE-2016-4491 triggers infinite recursion and a buffer overflow in the d_print_comp function, leading to a segmentation fault and crash.
What software is affected by CVE-2016-4491?
CVE-2016-4491 affects the following software: binutils (versions up to 2.29), gdb (version 8.0-0ubuntu3), libiberty (versions up to 20131116-1ubuntu0.2), and valgrind (versions up to 1:3.12.0-1.1ubuntu2).
How can I fix CVE-2016-4491?
To fix CVE-2016-4491, upgrade binutils to version 2.29 or later, gdb to version 8.0-0ubuntu3 or later, libiberty to version 20131116-1ubuntu0.2 or later, and valgrind to version 1:3.12.0-1.1ubuntu2 or later.
Where can I find more information about CVE-2016-4491?
You can find more information about CVE-2016-4491 at the following references: [1] [2] [3].