Use-After-Free Vulnerability in libiberty Affects GCC
CVE-2016-4487
5.5MEDIUM
Summary
The libiberty component of the GNU Compiler Collection contains a use-after-free vulnerability that can be exploited by remote attackers. By crafting a specific binary, an attacker can trigger a denial of service condition, leading to segmentation faults and potential crashes of the application. This security flaw is particularly relevant for scenarios involving the analysis of untrusted binaries, where malicious inputs can lead to system instability.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved