Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-15847

Опубликовано: 02 сент. 2019
Источник: debian
EPSS Низкий

Описание

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gcc-7fixed7.4.0-12package
gcc-7ignoredbusterpackage
gcc-8fixed8.3.0-22package
gcc-8ignoredbusterpackage
gcc-9fixed9.2.1-7package

Примечания

  • https://gcc.gnu.org/bugzilla/show_bug.cgi?id=91481

EPSS

Процентиль: 65%
0.00494
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

CVSS3: 7.5
redhat
около 6 лет назад

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

CVSS3: 7.5
nvd
около 6 лет назад

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

CVSS3: 7.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.5
github
больше 3 лет назад

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

EPSS

Процентиль: 65%
0.00494
Низкий