CVE-2018-20673

ADVISORY - nist

Summary

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.

EPSS Score: 0.00045 (0.166)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Integer Overflow or Wraparound

Out-of-bounds Write

ADVISORY - redhat

Heap-based Buffer Overflow

Integer Overflow or Wraparound


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in