CVE Vulnerabilities

CVE-2015-3027

Published: Apr 10, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers to bypass a stack-guard protection mechanism via crafted input to an affected C program.

Affected Software

NameVendorStart VersionEnd Version
XcodeApple*6.2 (including)
LlvmUbuntulucid*
Llvm-toolchain-3.3Ubuntuprecise*
Llvm-toolchain-3.3Ubuntutrusty*
Llvm-toolchain-3.3Ubuntuutopic*
Llvm-toolchain-3.4Ubuntuprecise*
Llvm-toolchain-3.4Ubuntutrusty*
Llvm-toolchain-3.4Ubuntuutopic*
Llvm-toolchain-3.4Ubuntuvivid*
Llvm-toolchain-3.4Ubuntuwily*
Llvm-toolchain-3.5Ubuntuesm-apps/xenial*
Llvm-toolchain-3.5Ubuntuutopic*
Llvm-toolchain-3.5Ubuntuvivid*
Llvm-toolchain-3.5Ubuntuwily*
Llvm-toolchain-3.5Ubuntuxenial*
Llvm-toolchain-3.5Ubuntuyakkety*
Llvm-toolchain-3.6Ubuntuesm-infra-legacy/trusty*
Llvm-toolchain-3.6Ubuntuesm-infra/xenial*
Llvm-toolchain-3.6Ubuntutrusty*
Llvm-toolchain-3.6Ubuntutrusty/esm*
Llvm-toolchain-3.6Ubuntuutopic*
Llvm-toolchain-3.6Ubuntuvivid*
Llvm-toolchain-3.6Ubuntuvivid/stable-phone-overlay*
Llvm-toolchain-3.6Ubuntuwily*
Llvm-toolchain-3.6Ubuntuxenial*
Llvm-toolchain-3.6Ubuntuyakkety*
Llvm-toolchain-snapshotUbuntutrusty*

References