Denial of Service Vulnerability in libiberty of GNU Compiler Collection
CVE-2016-4493

5.5MEDIUM

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
24 February 2017

Summary

The vulnerability in the demangle_template_value_parm and do_hpacc_template_literal functions within cplus-dem.c of libiberty can be exploited by remote attackers. By crafting specific binaries, these attackers can trigger an out-of-bounds read, potentially leading to a crash of the affected GCC software. This poses a significant risk during the analysis of untrusted binaries, as the flaw may be exploited to disrupt services and compromise system stability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.