CVE Database
/

CVE-2008-1685

Back to search

CVE-2008-1685

Published: Apr 6, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999)

VendorProductVersions

n/a

n/a

affected
n/a

References

gcc-weak-security(41686)
vdb-entry
x_refsource_XF
VU#162289
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now