CVE-2018-12698
7.5
HIGH
CVSS 3.1
EPSS 6.7%
Description
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
How to fix CVE-2018-12698
To remediate CVE-2018-12698, upgrade the affected package to a fixed version below.
- Debian/binutils—upgrade to 2.32.51.20190707-1 or later
Is CVE-2018-12698 being exploited?
Moderate — EPSS is 6.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.32.51.20190707-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |