CVE-2017-13716 PUBLISHED

The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).

EPSS 0.24% · 46.6th percentile

Risk Scores

EPSS Score
0.24%
46.6th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSbinutils2.41-5ubuntu1, 0, 2.42-4ubuntu2.8
Ubuntu:22.04:LTSlibiberty20211102-1, 0, 20211102-1build1
Ubuntu:25.10libiberty20250315-1, 0
Ubuntu:18.04:LTSlibiberty20170913-1ubuntu0.1, 20170913-1, 0
Ubuntu:Pro:14.04:LTSbinutils0, 2.23.52.20130913-0ubuntu1, 2.23.90.20131017-1ubuntu1
Ubuntu:Pro:20.04:LTSbinutils0, 2.34-6ubuntu1.5, 2.34-6ubuntu1.4
Ubuntu:22.04:LTSbinutils2.38-4ubuntu2.4, 2.38-4ubuntu2.3, 2.38-4ubuntu2.2
Ubuntu:Pro:16.04:LTSbinutils0, 2.26.1-1ubuntu1~16.04.4, 2.26.1-1ubuntu1~16.04.5
Ubuntu:20.04:LTSlibiberty0, 20200409-1, 20190907-1
Ubuntu:25.10binutils2.45-1ubuntu1, 2.45-7ubuntu1, 2.45-7ubuntu1.1
Ubuntu:16.04:LTSlibiberty20141014-1, 0, 20160215-1
Ubuntu:24.04:LTSlibiberty0, 20240117-1, 20240117-1build1
Ubuntu:Pro:18.04:LTSbinutils2.30-21ubuntu1~18.04, 2.30-20ubuntu2~18.04, 2.30-15ubuntu1

Timeline

References

Open in Interactive Console →