CVE-2015-3027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
10/04/2015
Last modified:
12/04/2025

Description

Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers to bypass a stack-guard protection mechanism via crafted input to an affected C program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:* 6.2 (including)