PT-2019-6470 · Gnu+1 · Gcc+1

Published

2014-03-15

·

Updated

2019-10-31

·

CVE-2002-2439

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gcc versions prior to 4.8.0
Description The issue is related to an integer overflow in the new[] operator, which can lead to heap overflows and security bugs. When a new array is allocated, the C++ run-time calculates its size, but if the product exceeds the maximum value that can be stored in a machine register, the error is ignored, and the truncated value is used for the heap allocation.
Recommendations For gcc versions prior to 4.8.0, update to version 4.8.0 or later to resolve the issue. As a temporary workaround, consider implementing additional checks to prevent integer overflows when using the new[] operator. Restrict access to sensitive data and functions that utilize the new[] operator to minimize the risk of exploitation.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1297
CVE-2002-2439

Affected Products

Alt Linux
Gcc