Heap-based out-of-bounds read in Binutils - CVE-2018-20712
Published: January 21, 2019
Binutils
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a heap-based buffer over-read in the function d_expression_1 in cp-demangle.c in GNU libiberty. A remote attacker can pass specially crafted data to the application, trigger segmentation faults and read contents of memory on the system.