CVE-2008-1367

gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
gnugcc
4.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glibc
bullseye
2.31-13+deb11u11
fixed
etch
not-affected
bullseye (security)
2.31-13+deb11u10
fixed
bookworm
2.36-9+deb12u8
fixed
bookworm (security)
2.36-9+deb12u7
fixed
sid
2.40-3
fixed
trixie
2.40-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gcc-4.3
hardy
dne
gutsy
dne
feisty
dne
edgy
dne
dapper
dne
glibc
hardy
not-affected
gutsy
not-affected
feisty
not-affected
edgy
not-affected
dapper
not-affected
linux
hardy
not-affected
gutsy
dne
feisty
dne
edgy
dne
dapper
dne
linux-source-2.6.15
hardy
dne
gutsy
dne
feisty
dne
edgy
dne
dapper
not-affected
linux-source-2.6.17
hardy
dne
gutsy
dne
feisty
dne
edgy
not-affected
dapper
dne
linux-source-2.6.20
hardy
dne
gutsy
dne
feisty
not-affected
edgy
dne
dapper
dne
linux-source-2.6.22
hardy
dne
gutsy
not-affected
feisty
dne
edgy
dne
dapper
dne
Common Weakness Enumeration
References