The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions d_name(), d_encoding(), and d_local_name() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.
Base Score: 4.3
Impact Score: 2.9
Exploitability Score: 8.6
Base Score: 5.5
Impact Score: 3.6
Exploitability Score: 1.8
|151919||Ubuntu 16.04 LTS : GNU binutils vulnerabilities (USN-4336-2)||Nessus||Ubuntu Local Security Checks|
|135966||Ubuntu 18.04 LTS : GNU binutils vulnerabilities (USN-4336-1)||Nessus||Ubuntu Local Security Checks|
|135398||Ubuntu 16.04 LTS / 18.04 LTS : libiberty vulnerabilities (USN-4326-1)||Nessus||Ubuntu Local Security Checks|
|122027||Photon OS 2.0: Binutils PHSA-2019-2.0-0119||Nessus||PhotonOS Local Security Checks|
|121563||Fedora 29 : binutils (2019-ba3cbcfd20)||Nessus||Fedora Local Security Checks|