Wind River Support Network

HomeDefectsLIN7-6230
Fixed

LIN7-6230 : Security Advisory - gcc - CVE-2016-4490

Created: May 19, 2016    Updated: Sep 8, 2018
Resolved Date: Jun 12, 2016
Found In Version: 7.0
Fix Version: 7.0.0.17
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Toolchain

Description

A vulnerability was found in gcc. Due to the inconsistent use of long and int for string/array length in cp-demangle.c there is an integer overflow that leads to a write access violation. The target crashes on an access violation at an address matching the destination operand of the instruction.

External references:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70498

Upstream patch:

https://gcc.gnu.org/viewcvs/gcc?view=revision&revision=235767

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4490

Other Downloads


CVEs


Live chat
Online