{"id":"CVE-2017-7892","details":"Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap'n Proto relies on pointer arithmetic calculations that overflow. An example compiler with optimization that elides a bounds check in such calculations is Apple LLVM version 8.1.0 (clang-802.0.41). The attack vector is a crafted far pointer within a message.","modified":"2026-07-08T16:54:18.268112Z","published":"2017-04-17T21:59:00.403Z","references":[{"type":"ADVISORY","url":"https://github.com/sandstorm-io/capnproto/blob/master/security-advisories/2017-04-17-0-apple-clang-elides-bounds-check.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/capnproto/capnproto","events":[{"introduced":"0"},{"last_affected":"133b496e09fdb9937a364a12b69385f2dbcc9cdb"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.5.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:capnproto:capnproto:*:*:*:*:*:*:*:*"}}],"versions":["v0.5.3","v0.5.2","v0.5.1.2","v0.5.1.1","v0.5.1","v0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7892.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}