Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1367
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1367

Description:
gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41340

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html
  http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00000.html
  http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.html

SAID
  Secunia Advisory: SA30850
  Secunia Advisory: SA30818
  Secunia Advisory: SA30890
  Secunia Advisory: SA30962
  Secunia Advisory: SA31246
  Secunia Advisory: SA30110
  Secunia Advisory: SA30116

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0211.html
  http://www.redhat.com/support/errata/RHSA-2008-0233.html
  http://rhn.redhat.com/errata/RHSA-2008-0508.html

MLIST
  http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00499.html
  http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00432.html
  http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00428.html
  http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00417.html
  http://lkml.org/lkml/2008/3/5/207
  http://lists.vmware.com/pipermail/security-announce/2008/000023.html
  http://marc.info/?l=git-commits-head&m=120492000901739&w=2

MISC
  http://lwn.net/Articles/272048/#Comments

CONFIRM
  http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e40cd10ccff3d9fbffd57b93780bee4b7b9bff51
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469058

BID
  29084


Return to the previous page.