CVE-2008-1685
Published: 6 April 2008
** DISPUTED ** gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999).
Notes
Author | Note |
---|---|
jdstrand | gcc-4.3 exists in main, so watch for Intrepid and later |
mdeslaur | upstream says this isn't an issue: http://gcc.gnu.org/ml/gcc/2008-04/msg00115.html |
Priority
Status
Package | Release | Status |
---|---|---|
gcc-4.2 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
edgy |
Does not exist
|
|
feisty |
Does not exist
|
|
gutsy |
Ignored
(end of life, was needed)
|
|
hardy |
Ignored
|
|
intrepid |
Ignored
|
|
jaunty |
Ignored
|
|
karmic |
Ignored
|
|
upstream |
Ignored
|
|
gcc-4.3 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
edgy |
Does not exist
|
|
feisty |
Does not exist
|
|
gutsy |
Does not exist
|
|
hardy |
Does not exist
|
|
intrepid |
Ignored
|
|
jaunty |
Ignored
|
|
karmic |
Ignored
|
|
upstream |
Ignored
|