Candidate: CVE-2017-7892 PublicDate: 2017-04-17 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7892 https://github.com/sandstorm-io/capnproto/blob/master/security-advisories/2017-04-17-0-apple-clang-elides-bounds-check.md Description: Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap'n Proto relies on pointer arithmetic calculations that overflow. An example compiler with optimization that elides a bounds check in such calculations is Apple LLVM version 8.1.0 (clang-802.0.41). The attack vector is a crafted far pointer within a message. Ubuntu-Description: Kenton Varda discovered that the Cap'n Proto utility has a buffer overflow vulnerability. An attacker could use this vulnerability to cause a crash or possibly execute arbitrary code. Notes: ratliff> Advisory: "Some bounds checks are elided by Apple's compiler and possibly others, leading to a possible attack especially in 32-bit builds." ratliff> Setting status to needs-triage to investigate whether it impacts Ubuntu Bugs: Priority: low Discovered-by: Kenton Varda Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_capnproto: upstream_capnproto: released (0.5.3.1) precise_capnproto: DNE precise/esm_capnproto: DNE trusty_capnproto: released (0.4.0-1ubuntu2.1) trusty/esm_capnproto: DNE (trusty was released [0.4.0-1ubuntu2.1]) vivid/stable-phone-overlay_capnproto: ignored (reached end-of-life) vivid/ubuntu-core_capnproto: DNE xenial_capnproto: released (0.5.3-2ubuntu1.1) esm-infra/xenial_capnproto: released (0.5.3-2ubuntu1.1) yakkety_capnproto: ignored (reached end-of-life) zesty_capnproto: ignored (reached end-of-life) artful_capnproto: ignored (reached end-of-life) bionic_capnproto: released (0.6.1-1) devel_capnproto: released (0.6.1-1)