CVE-2016-2226 PUBLISHED

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

EPSS 9.33% · 92.7th percentile

Risk Scores

EPSS Score
9.33%
92.7th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10binutils-h8300-hms2.16.1-10build1, 0
Ubuntu:20.04:LTSbinutils-h8300-hms2.16.1-10build1, 0
Ubuntu:20.04:LTSgcc-h8300-hms1:3.4.6+dfsg2-4.1, 1:3.4.6+dfsg2-4ubuntu3, 0
Ubuntu:16.04:LTSsdcc3.4.0+dfsg-2ubuntu1, 3.5.0+dfsg-2, 3.5.0+dfsg-1
Ubuntu:Pro:16.04:LTSbinutils2.26.1-1ubuntu1~16.04.5, 0, 2.25.1-6ubuntu1
Ubuntu:16.04:LTSht2.1.0-1build1, 0, 2.1.0-1
Ubuntu:22.04:LTSnescc0, 1.3.5-1.1build1
Ubuntu:16.04:LTSgcc-h8300-hms0, 1:3.4.6+dfsg2-4ubuntu1
Ubuntu:16.04:LTSgccxml0, 0.9.0+git20140716-6
Ubuntu:14.04:LTSvalgrind1:3.8.1-5ubuntu3, 1:3.8.1-5ubuntu2, 1:3.8.1-5ubuntu1
Ubuntu:18.04:LTSnescc0, 1.3.5-1, 1.3.5-1.1
Ubuntu:Pro:14.04:LTSbinutils2.24-5ubuntu14.2+esm5, 2.24-5ubuntu14.2+esm6, 2.24-5ubuntu14.2+esm7
Ubuntu:24.04:LTSgcc-h8300-hms1:3.4.6+dfsg2-4.2, 0
Ubuntu:16.04:LTSgdb7.11-0ubuntu1, 7.10.90.20160220-0ubuntu1, 7.11.1-0ubuntu1~16.04
Ubuntu:18.04:LTSsdcc3.5.0+dfsg-2, 0, 3.5.0+dfsg-2build1
Ubuntu:20.04:LTSnescc1.3.5-1.1build1, 0
Ubuntu:18.04:LTSgcc-h8300-hms0, 1:3.4.6+dfsg2-4ubuntu1, 1:3.4.6+dfsg2-4ubuntu3
Ubuntu:14.04:LTSlibiberty20131116-1, 0
Ubuntu:24.04:LTSbinutils-h8300-hms2.16.1-10build1, 0
Ubuntu:22.04:LTSgcc-h8300-hms1:3.4.6+dfsg2-4.1, 0, 1:3.4.6+dfsg2-4.2

…and 9 more

Timeline

References

Open in Interactive Console →