remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Link | Tags |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=23059 | issue tracking exploit vendor advisory |
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85453 | issue tracking exploit vendor advisory |
https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763101 | issue tracking |
https://usn.ubuntu.com/4326-1/ | vendor advisory |
https://usn.ubuntu.com/4336-1/ | vendor advisory |