CVE-2018-20657 describes a memory leak vulnerability in the demangle_template function of GNU libiberty, specifically within GNU Binutils 2.31.1. This flaw, related to CVE-2018-12698, can be triggered by a crafted string, leading to a denial of service through excessive memory consumption, as demonstrated by the cxxfilt utility. Affected products include various versions of GNU Binutils and F5 Traffix Signaling Delivery Controller. The vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a critical severity. It can be exploited remotely over the network with low attack complexity and no user interaction required (AV:N/AC:L/PR:N/UI:N). The primary impact is a high availability compromise (A:H), meaning systems could become unresponsive. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention from researchers or the public.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.31.1CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.31.1:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.1.0CPE matchmatch criteria | cpe:2.3:a:f5:traffix_signaling_delivery_controller:*:*:*:*:*:*:*:* | ||
4.4.0CPE matchmatch criteria | cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.