VDB

CVE-2016-4491

CVE-2016-4491 PUBLISHED

The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and a buffer overflow, related to a node having "itself as ancestor more than once."

EPSS 0.52% · 67.2th percentile

Risk Scores

EPSS Score
0.52%
67.2th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSgcc-h8300-hms1:3.4.6+dfsg2-4.2, *, 0
Ubuntu:16.04:LTSht0, 2.1.0-1, 2.1.0-1build1
Ubuntu:16.04:LTSgdb7.11-0ubuntu1, 0, 7.10-1ubuntu2
Ubuntu:18.04:LTSgcc-h8300-hms*, 0, 1:3.4.6+dfsg2-4ubuntu1
Ubuntu:16.04:LTSnescc1.3.5-1, 0
Ubuntu:22.04:LTSbinutils-h8300-hms0, 2.16.1-10build1
Ubuntu:25.10gcc-h8300-hms0, 1:3.4.6+dfsg2-4.2
Ubuntu:14.04:LTSlibiberty20131116-1, 0
Ubuntu:16.04:LTSlibiberty20160215-1, 0, 20141014-1
Ubuntu:16.04:LTSsdcc0, 3.4.0+dfsg-2ubuntu1, 3.5.0+dfsg-1
Ubuntu:14.04:LTSgdb7.7.1-0ubuntu5~14.04.2, 7.7-0ubuntu3, 0
Ubuntu:20.04:LTSnescc1.3.5-1.1build1, 0
Ubuntu:24.04:LTSgcc-h8300-hms*, 0
Ubuntu:24.04:LTSbinutils-h8300-hms0, 2.16.1-10build1
Ubuntu:20.04:LTSgcc-h8300-hms0, 1:3.4.6+dfsg2-4.1, *
Ubuntu:16.04:LTSbinutils-h8300-hms2.16.1-10, 0
Ubuntu:16.04:LTSgcc-h8300-hms1:3.4.6+dfsg2-4ubuntu1, 0
Ubuntu:22.04:LTSnescc0, 1.3.5-1.1build1
Ubuntu:Pro:14.04:LTSbinutils2.24-5ubuntu13, 0, 2.23.90.20131017-1ubuntu1
Ubuntu:16.04:LTSgcc-arm-none-eabi15:4.9.3+svn227297-1, 15:4.9.3+svn227297-1build1, *

…and 10 more

Timeline

  • Feb 24, 2017 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›