Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and int types for lengths.
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70498