First published: Sat Jun 23 2018(Updated: )
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.30 | |
Canonical Ubuntu Linux | =16.04.4 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12698 is a vulnerability in GNU Binutils 2.30 that allows attackers to trigger excessive memory consumption.
CVE-2018-12698 can lead to an out-of-memory (OOM) condition during execution of objdump.
CVE-2018-12698 affects GNU Binutils 2.30 and potentially other versions as well.
To address CVE-2018-12698, you should update your GNU Binutils package to version 2.30-21ubuntu1~18.04.3 or later.
You can find more information about CVE-2018-12698 at the following references: [1](https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102), [2](https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454), [3](https://sourceware.org/bugzilla/show_bug.cgi?id=23057)