Severity
5.5
Medium severity
Details
- CVSS score
- 5.5
- CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Overview
About vulnerability
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for “Create an array for saving the template argument values”) that can trigger a heap-based buffer overflow, as demonstrated by nm.Details
- Affected product:
- CentOS 8.4 ELS , CentOS 8.5 ELS , Debian 10 ELS
- Affected packages:
- binutils @ 2.31.1 (+4 more)