CVE-2018-18483: Integer Overflow
Last updated 18 August 2025
Other sources
The getcount function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string, as demonstrated by c++filt.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3Fixed in 2.46.90.20260712-1
Event History
Frequently Asked Questions
What is CVE-2018-18483?
CVE-2018-18483 is a vulnerability in GNU libiberty as distributed in GNU Binutils 2.31 that allows remote attackers to cause a denial of service or possibly have unspecified other impact.
How can CVE-2018-18483 be exploited?
CVE-2018-18483 can be exploited by remote attackers using a crafted string to trigger a denial of service or other unspecified impact.
What software is affected by CVE-2018-18483?
Ubuntu binutils versions 2.30-21ubuntu1~18.04.3 (bionic) and 2.26.1-1ubuntu1~16.04.8+ (xenial), as well as Ubuntu libiberty versions 20170913-1ubuntu0.1 (bionic) and 20160215-1ubuntu0.3 (xenial) are affected by CVE-2018-18483.
How can I fix the CVE-2018-18483 vulnerability on Ubuntu?
For Ubuntu bionic, upgrade the binutils package to version 2.30-21ubuntu1~18.04.3 or later, and for Ubuntu xenial, upgrade the binutils package to version 2.26.1-1ubuntu1~16.04.8+ or later, and upgrade the libiberty package to version 20170913-1ubuntu0.1 or later.
Where can I find more information about CVE-2018-18483?
You can find more information about CVE-2018-18483 at the following references: [CVE-2018-18483 on gcc.gnu.org](https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87602), [CVE-2018-18483 on sourceware.org](https://sourceware.org/bugzilla/show_bug.cgi?id=23767), [CVE-2018-18483 on securityfocus.com](http://www.securityfocus.com/bid/105689).