Wind River Support Network

HomeDefectsLIN5-21537
Fixed

LIN5-21537 : Security Advisory - gcc - CVE-2016-4489

Created: May 19, 2016    Updated: May 29, 2018
Resolved Date: Aug 11, 2016
Found In Version: 5.0.1.35
Fix Version: 5.0.1.37
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Toolchain

Description

A vulnerability was found in gcc. It's possible to achieve an invalid write of size 8 due to an integer overflow in the demangling of virtual tables in method gnu_special.

External references:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70492

Upstream fix:

https://gcc.gnu.org/viewcvs/gcc?view=revision&revision=234828

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4489

Other Downloads


Live chat
Online