gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.
References
Link Providers
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469058 cve-icon cve-icon
http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00417.html cve-icon cve-icon
http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00428.html cve-icon cve-icon
http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00432.html cve-icon cve-icon
http://gcc.gnu.org/ml/gcc-patches/2008-03/msg00499.html cve-icon cve-icon
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e40cd10ccff3d9fbffd57b93780bee4b7b9bff51 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00000.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2008/000023.html cve-icon cve-icon
http://lkml.org/lkml/2008/3/5/207 cve-icon cve-icon
http://lwn.net/Articles/272048/#Comments cve-icon cve-icon
http://marc.info/?l=git-commits-head&m=120492000901739&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2008-0508.html cve-icon cve-icon
http://secunia.com/advisories/30110 cve-icon cve-icon
http://secunia.com/advisories/30116 cve-icon cve-icon
http://secunia.com/advisories/30818 cve-icon cve-icon
http://secunia.com/advisories/30850 cve-icon cve-icon
http://secunia.com/advisories/30890 cve-icon cve-icon
http://secunia.com/advisories/30962 cve-icon cve-icon
http://secunia.com/advisories/31246 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0211.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0233.html cve-icon cve-icon
http://www.securityfocus.com/bid/29084 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2222/references cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=437312 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/41340 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-1367 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11108 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-1367 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2008-03-17T23:00:00

Updated: 2024-08-07T08:17:34.582Z

Reserved: 2008-03-17T00:00:00

Link: CVE-2008-1367

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-03-17T23:44:00.000

Modified: 2023-11-07T02:01:56.410

Link: CVE-2008-1367

cve-icon Redhat

Severity : Low

Publid Date: 2008-03-05T00:00:00Z

Links: CVE-2008-1367 - Bugzilla