Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-1685

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.2%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2008-1685
  • Gnu » Gcc » Version: 4.2.0
    cpe:2.3:a:gnu:gcc:4.2.0
  • Gnu » Gcc » Version: 4.2.1
    cpe:2.3:a:gnu:gcc:4.2.1
  • Gnu » Gcc » Version: 4.2.2
    cpe:2.3:a:gnu:gcc:4.2.2
  • Gnu » Gcc » Version: 4.2.3
    cpe:2.3:a:gnu:gcc:4.2.3
  • Gnu » Gcc » Version: 4.2.4
    cpe:2.3:a:gnu:gcc:4.2.4
  • Gnu » Gcc » Version: 4.3.0
    cpe:2.3:a:gnu:gcc:4.3.0


Contact Us

Shodan ® - All rights reserved