[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-12886 -- gcc-8, gcc-7, gcc-6

ID: oval:org.secpod.oval:def:2003565Date: (C)2020-09-25   (M)2021-11-24
Class: VULNERABILITYFamily: unix




stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection 4.1 through 8 generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.

Platform:
Debian 10.x
Debian 9.x
Product:
gcc-8
gcc-7
gcc-6
Reference:
CVE-2018-12886
CVE    1
CVE-2018-12886
CPE    5
cpe:/o:debian:debian_linux:10.x
cpe:/a:gnu:gcc-8
cpe:/a:gnu:gcc-6
cpe:/o:debian:debian_linux:9.x
...

© SecPod Technologies