Bugzilla – Bug 978816
VUL-1: CVE-2016-4490: gcc: Write access violation
Last modified: 2023-02-08 16:51:13 UTC
rh#1333366 / CVE-2016-4490 A vulnerability was found in gcc. Due to the inconsistent use of long and int for string/array length in cp-demangle.c there is an integer overflow that leads to a write access violation. The target crashes on an access violation at an address matching the destination operand of the instruction. External references: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70498 Upstream patch: https://gcc.gnu.org/viewcvs/gcc?view=revision&revision=235767 References: https://bugzilla.redhat.com/show_bug.cgi?id=1333366 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4490 http://seclists.org/oss-sec/2016/q2/240
bugbot adjusting priority
Bug in name demangling -> VUL-1
Fixed since a long time. (when libiberty, and hence binutils was affected: by version updates to binutils for sle-12 and sle-15 and sle-11 wontfix)