CVE-2002-2439
published 2019-10-23CVE-2002-2439: Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.55%
42.0th percentile
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gcc | < 4.8.0 | 4.8.0 |
| gnu | gcc | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm8j-7g3h-x2mj: Integer overflow in the new[] operator in gcc before 4
ghsa_unreviewed·2022-04-21
CVE-2002-2439 [HIGH] CWE-190 GHSA-mm8j-7g3h-x2mj: Integer overflow in the new[] operator in gcc before 4
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
OSV
CVE-2002-2439: operator new[] sometimes returns pointers to heap blocks which are too small
osv·2019-10-23·CVSS 7.8
CVE-2002-2439 [HIGH] CVE-2002-2439: operator new[] sometimes returns pointers to heap blocks which are too small
operator new[] sometimes returns pointers to heap blocks which are too small. When a new array is allocated, the C++ run-time has to calculate its size. The product may exceed the maximum value which can be stored in a machine register. This error is ignored, and the truncated value is used for the heap allocation. This may lead to heap overflows and therefore security bugs. (See http://cert.uni-stuttgart.de/advisories/calloc.php for further references.)
Red Hat
gcc: Integer overflow can occur during the computation of the memory region size for new[] operator
vendor_redhat·2002-08-05·CVSS 7.8
CVE-2002-2439 [HIGH] CWE-190 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator
gcc: Integer overflow can occur during the computation of the memory region size for new[] operator
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
Package: compat-gcc-295 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-296 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-32 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-34 (Red Hat Enterprise Linux 5) - Will not fix
Package: gcc (Red Hat Enterprise Linux 5) - Will not fix
Package: gcc43 (Red Hat Enterprise Linux 5) - Will not fix
Package: gcc44 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-295 (Red Hat Enterprise Linux 6) - Will not fix
Package: compat-gcc-296 (Red Hat Enterprise Linux 6) - Will not fix
Pac
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator [fedora-all]
bugzilla·2012-09-03·CVSS 7.8
CVE-2002-2439 [HIGH] CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator [fedora-all]
CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://
Bugzilla
CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator [fedora-all]
bugzilla·2012-09-03·CVSS 7.8
CVE-2002-2439 [HIGH] CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator [fedora-all]
CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://
Bugzilla
CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator
bugzilla·2012-09-03·CVSS 7.8
CVE-2002-2439 [HIGH] CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator
CVE-2002-2439 gcc: Integer overflow can occur during the computation of the memory region size for new[] operator
It was reported that C++ new[] operator was previously missing integer overflow / wrap around checks for its arguments. If an application compiled with gcc accepted untrusted input for memory allocation and was missing application-level checks for integer overflows of arguments, provided to the new[] operator, an attacker could use this flaw to cause the memory region, allocated in the end for the new[] operator statement, it to be smaller than truly required, possibly leading to heap-based buffer overflows.
Upstream bug report:
[1] http://gcc.gnu.org/bugzilla/show_bug.cgi?id=19351
Upstream patches:
[2] http://gcc.gnu.org/ml/gcc-patches/2012-06/msg01689.html
[3] http://gcc.g
https://access.redhat.com/security/cve/cve-2002-2439https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2002-2439https://gcc.gnu.org/bugzilla/show_bug.cgi?id=19351https://security-tracker.debian.org/tracker/CVE-2002-2439https://access.redhat.com/security/cve/cve-2002-2439https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2002-2439https://gcc.gnu.org/bugzilla/show_bug.cgi?id=19351https://security-tracker.debian.org/tracker/CVE-2002-2439
2019-10-23
Published