Wind River Support Network

HomeDefectsLIN8-3650
Fixed

LIN8-3650 : Security Advisory - gcc - CVE-2016-2226

Created: May 19, 2016    Updated: Dec 3, 2018
Resolved Date: May 19, 2016
Found In Version: 8.0
Fix Version: 8.0.0.6
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Toolchain

Description

A vulnerability was found in gcc. Specifically, it revolves around demangling while analysing the untrusted binaries. A particularly malicious attacker could craft an executable that executes when *analysed* by objdump, nm or gdb, or any other libbfd / libiberty - based forensics tool (if the demangling option is switched on).

External references:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=69687

References:

http://seclists.org/oss-sec/2016/q2/238

Upstream fix:

https://gcc.gnu.org/viewcvs/gcc?view=revision&revision=234829

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2226

Other Downloads


CVEs


Live chat
Online