Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1685

Опубликовано: 06 апр. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999)

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:gcc:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00487
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 17 лет назад

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999)

redhat
больше 17 лет назад

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999)

debian
больше 17 лет назад

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not ...

github
больше 3 лет назад

** DISPUTED ** gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999).

CVSS3: 8.6
fstec
больше 17 лет назад

Уязвимость набора компиляторов для различных языков программирования GNU Compiler Collection (GCC), связанная с некорректной обработкой суммы указателя и целого числа, позволяющая нарушителю вызвать отказ в обслуживании или оказать иное воздействие

EPSS

Процентиль: 64%
0.00487
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-119