CVE-2018-12698
Last modified
CVE-2018-12698 is a vulnerability of currently unknown severity. demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.. EPSS estimates a 6.69% chance of exploitation in the next 30 days.
Description
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | 2.30 |
| Canonical | Ubuntu Linux | 16.04.4 |
References
- http://www.securityfocus.com/bid/104539Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102Exploit, Third Party Advisory
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454Exploit, Issue Tracking, Vendor Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=23057Exploit, Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/104539Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102Exploit, Third Party Advisory
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454Exploit, Issue Tracking, Vendor Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=23057Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12698?
How severe is CVE-2018-12698?
How do I fix CVE-2018-12698?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12692TP-Link TL-WA850RE Wi-Fi Range Extender with hardware versio…
- CVE-2018-12693Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Rang…
- CVE-2018-12694TP-Link TL-WA850RE Wi-Fi Range Extender with hardware versio…
- CVE-2018-12695mao10cms 6 allows XSS via the m=bbs&a=index page.
- CVE-2018-12696mao10cms 6 allows XSS via the article page.
- CVE-2018-12697A NULL pointer dereference (aka SEGV on unknown address 0x00…
- CVE-2018-12699finish_stab in stabs.c in GNU Binutils 2.30 allows attackers…
- CVE-2018-1270Spring Framework, versions 5.0 prior to 5.0.5 and versions 4…9.8
- CVE-2018-12700Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-12702The approveAndCallcode function of a smart contract implemen…
- CVE-2018-12703The approveAndCallcode function of a smart contract implemen…
- CVE-2018-12705DIGISOL DG-BR4000NG devices have XSS via the SSID (it is val…
Are you affected by CVE-2018-12698?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
