CVE-2018-20673: Buffer Overflow
The demangletemplate function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20673?
CVE-2018-20673 is classified as a high severity vulnerability due to the potential for a heap-based buffer overflow.
How do I fix CVE-2018-20673?
To fix CVE-2018-20673, users should upgrade to a fixed version of GNU Binutils that addresses the integer overflow issue.
What causes the CVE-2018-20673 vulnerability?
CVE-2018-20673 is caused by an integer overflow in the demangle_template function that can lead to a heap-based buffer overflow.
What are the potential impacts of CVE-2018-20673?
The potential impacts of CVE-2018-20673 include arbitrary code execution and application crashes due to the buffer overflow.
Which versions of GNU Binutils are affected by CVE-2018-20673?
CVE-2018-20673 affects GNU Binutils version 2.31.1.