Wind River Support Network


LIN6-11283 : Security Advisory - gcc - CVE-2016-4490

Created: May 19, 2016    Updated: Dec 3, 2018
Resolved Date: Jul 4, 2016
Found In Version: 6.0
Fix Version:
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Toolchain


A vulnerability was found in gcc. Due to the inconsistent use of long and int for string/array length in cp-demangle.c there is an integer overflow that leads to a write access violation. The target crashes on an access violation at an address matching the destination operand of the instruction.

External references:

Upstream patch:

Other Downloads

Live chat