Source: tcc
Version: 0.9.27-8
Severity: normal
Tags: security upstream
Forwarded: 
https://lists.nongnu.org/archive/html/tinycc-devel/2019-05/msg00044.html

Hi,

The following vulnerability was published for tcc.

CVE-2019-12495[0]:
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27.
| Compiling a crafted source file leads to a one-byte out-of-bounds
| write in the gsym_addr function in x86_64-gen.c. This occurs because
| tccasm.c mishandles section switches.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-12495
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12495
[1] https://lists.nongnu.org/archive/html/tinycc-devel/2019-05/msg00044.html
[2] 
https://repo.or.cz/tinycc.git/commit/d04ce7772c2bc2781ab2502e0b1f1964488814b5

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to