CVE-2018-12886
published 2019-05-22CVE-2018-12886: stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances)…
PriorityP348high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.17%
80.2th percentile
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gcc | 4.1 – 8.0 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mwp-7q9c-cgg2: stack_protect_prologue in cfgexpand
ghsa_unreviewed·2022-05-24
CVE-2018-12886 [HIGH] GHSA-5mwp-7q9c-cgg2: stack_protect_prologue in cfgexpand
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.
OSV
CVE-2018-12886: stack_protect_prologue in cfgexpand
osv·2019-05-22·CVSS 8.1
CVE-2018-12886 [HIGH] CVE-2018-12886: stack_protect_prologue in cfgexpand
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SCALANCE Third-Party
cisa_ics·2023-03-21
Siemens SCALANCE Third-Party
ICS Advisory
##
Siemens SCALANCE Third-Party
Release DateMarch 21, 2023
Alert CodeICSA-23-080-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: Various third-party components used in SCALANCE W-700 devices
- Vulnerabilities: Generation of Error Message Containing Sensitive Information, Out-of-bounds Write, NULL Pointer Dereference, Out-of-bounds Read, Improper Input Validation, Release of Inval
Red Hat
gcc: spilling of stack protection address in cfgexpand.c and function.c leads to stack-overflow protection bypass
vendor_redhat·2019-05-22·CVSS 8.1
CVE-2018-12886 [HIGH] CWE-119 gcc: spilling of stack protection address in cfgexpand.c and function.c leads to stack-overflow protection bypass
gcc: spilling of stack protection address in cfgexpand.c and function.c leads to stack-overflow protection bypass
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.
Package: gcc (Red Hat Enterprise Linux 4) - Not affected
Package: gcc4 (Red Hat Enterprise Linux 4) - Not affected
Package: gcc (Red Hat Enterprise Linux 5) - Not affected
Package:
No detection rules found.
No public exploits indexed.
arXiv
Gotta Catch 'em All: Aggregating CVSS Scores
arxiv_fulltext·2023-10-03
Gotta Catch 'em All: Aggregating CVSS Scores
Gotta Catch 'em All: Aggregating CVSS Scores
1st Ángel Longueira-Romero, 2nd Jose Luis Flores, 3rd Rosa Iglesias
Industrial Cybersecurity
Ikerlan Technology Research Centre (BRTA)
Arrasate/Mondragón, Spain
\alongueira, jlflores, riglesias\@ikerlan.es
4th Iñaki Garitano
Dept. of Electronics and Computing
Mondragon Unibertsitatea
Arrasate/Mondragón, Spain
[email protected]
## Abstract
Security metrics are not standardized, but international proposals such as the Common Vulnerability Scoring System (CVSS) for quantifying the severity of known vulnerabilities are widely used. Many CVSS aggregation mechanisms have been proposed in the literature. Nevertheless, factors related to the context of the System Under Test (SUT) are not taken into account in the aggregation process; vul
Bugzilla
CVE-2018-12886 gcc: spilling of stack protection address in cfgexpand.c and function.c leads to stack-overflow protection bypass
bugzilla·2019-05-31·CVSS 8.1
CVE-2018-12886 [HIGH] CVE-2018-12886 gcc: spilling of stack protection address in cfgexpand.c and function.c leads to stack-overflow protection bypass
CVE-2018-12886 gcc: spilling of stack protection address in cfgexpand.c and function.c leads to stack-overflow protection bypass
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU GCC 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the stack protector guard address, which allows bypassing the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.
Upstream Issue:
https://gcc.gnu.org/viewcvs/gcc/trunk/gcc/config/arm/arm-protos.h?revision=266379&view=markup
2019-05-22
Published