UBUNTU-CVE-2018-12886
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12886
Summary:
Details: stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.
References: https://ubuntu.com/security/CVE-2018-12886, https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=89d7557202d25a393666ac4c0f7dbdab31e452a2, https://www.cve.org/CVERecord?id=CVE-2018-12886
Affected packages
Package
Name: gcc-4.8
Purl: pkg:deb/ubuntu/gcc-4.8?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
