Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11671

Опубликовано: 26 июл. 2017
Источник: debian
EPSS Низкий

Описание

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gcc-6fixed6.3.0-12package
gcc-5fixed5.4.1-10package
gcc-4.9removedpackage
gcc-4.9no-dsajessiepackage
gcc-4.8removedpackage
gcc-4.8no-dsajessiepackage
gcc-4.7removedpackage
gcc-4.7no-dsawheezypackage
gcc-4.6removedpackage
gcc-4.6no-dsawheezypackage

Примечания

  • http://openwall.com/lists/oss-security/2017/07/27/2

  • https://gcc.gnu.org/bugzilla/show_bug.cgi?id=80180

  • https://gcc.gnu.org/ml/gcc-patches/2017-03/msg01349.html

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

CVSS3: 4
ubuntu
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

CVSS3: 5.6
redhat
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

CVSS3: 4
nvd
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

suse-cvrf
около 8 лет назад

Security update for gcc48

suse-cvrf
около 8 лет назад

Security update for gcc48

EPSS

Процентиль: 31%
0.00115
Низкий