4.6
CVSSv2

CVE-2006-0635

Published: 10/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.

Vulnerable Product Search on Vulmon Subscribe to Product

fabrice bellard tiny c compiler 0.9.23

Vendor Advisories

Debian Bug report logs - #352202 CVE-2006-0635: Incorrect parsing of sizeof() may introduce integer overflows Package: tcc; Maintainer for tcc is Thomas Preud'homme <robotux@debianorg>; Source for tcc is src:tcc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 10 Feb 2006 12:03:02 UT ...