Source: tcc Version: 0.9.27-8 Severity: normal Tags: security upstream Forwarded: https://lists.nongnu.org/archive/html/tinycc-devel/2019-05/msg00044.html
Hi, The following vulnerability was published for tcc. CVE-2019-12495[0]: | An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. | Compiling a crafted source file leads to a one-byte out-of-bounds | write in the gsym_addr function in x86_64-gen.c. This occurs because | tccasm.c mishandles section switches. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-12495 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12495 [1] https://lists.nongnu.org/archive/html/tinycc-devel/2019-05/msg00044.html [2] https://repo.or.cz/tinycc.git/commit/d04ce7772c2bc2781ab2502e0b1f1964488814b5 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

