Improper Input Validation The advisory has been revoked - it doesn't affect any version of package gcc  (opens in a new tab)


Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-GCC-3013189
  • published1 Sept 2022
  • disclosed1 Sept 2022
  • creditUnknown

Introduced: 1 Sep 2022

CVE-2020-35536  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade gcc to version 10.1.0 or higher.

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Improper Input Validation where an internal compiler error in the match_reload function at lra-constraints.c can cause a crash through a crafted input file.

Note: CVE-2020-35536 - has been retracted because it was found to be invalid.