Integer Overflow Vulnerability in Libiberty Affects GCC
CVE-2016-4490

5.5MEDIUM

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
24 February 2017

What is CVE-2016-4490?

An integer overflow vulnerability in the cp-demangle.c file of the libiberty component of GCC can be exploited by remote attackers. By crafting a specific binary, an attacker can trigger a denial of service condition, leading to segmentation faults and crashes. This issue arises from inconsistent handling of type lengths, particularly between long and int types, which may lead to serious instability and service disruption when analyzing untrusted binaries.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2016-4490 : Integer Overflow Vulnerability in Libiberty Affects GCC