3 ms·
Here's a specific example for a C++ compiler: CVE-2019-0546 I have a feeling you could find Java ones too if you looked hard enough. Compilers are complex beas
by beefsack 8y ago
Here's a specific example for a C++ compiler: CVE-2019-0546
I have a feeling you could find Java ones too if you looked hard enough. Compilers are complex beasts.
[1]: https://nvd.nist.gov/vuln/detail/CVE-2019-0546 https://nvd.nist.gov/vuln/detail/CVE-2019-0546
- pcwalton 8y agoThat seems to be this one: https://www.thezdi.com/blog/2019/2/28/finding-unicorns-when-the-c-compiler-writes-the-vuln https://www.thezdi.com/blog/2019/2/28/finding-unicorns-when-... It's a straightforward miscompilation. I'm not sure why they even classify it as a vulnerability. From Microsoft, per the article: "The said vulnerability is about downloading and running untrusted code, which has always existed in all releases prior VS2017 Update 9 that supported lambdas. The scenario is not common coding practice and considering we've always had this in all our prior releases and have not seen any evidences of exploit it would not make sense to port the change as hotfix from 15.9 to prior VS releases." In other words, it's never made into a product in an exploitable way. I'd just call this a miscompilation.
- tedunangst 8y ago> If you’re still on the fence about deploying this update, we would consider it Important since it could allow for attacker-controlled code to execute at the level of the logged on user. What does that even mean? I download some c++ code from the internet, compile it, run it, and... it runs as my user?
- kllrnohj 8y agohttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0546 https://portal.msrc.microsoft.com/en-US/security-guidance/ad... > Exploitation of the vulnerability requires that a user open a specially crafted file which was compiled with an affected version of Visual Studio. In an email attack scenario, an attacker could exploit the vulnerability by sending a specially crafted project, or resource file, to the user and convince the user to open the file. So yeah sure looks like a basic code execution results in code execution. Surprised this even got a CVE.
- pcwalton 8y agoYeah, I think it means just that. I guess there is some conceivable exploit where you compile some hostile code written in a safe language to C++ with MSVC and then run it, and the attacker could exploit this bug somehow? But who does that?