Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-11671

Опубликовано: 26 июл. 2017
Источник: nvd
CVSS3: 4
CVSS2: 2.1
EPSS Низкий

Описание

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:gcc:4.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:4.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:5.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:5.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:5.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:5.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:5.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:6.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:6.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:6.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gcc:6.3:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00115
Низкий

4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 4
ubuntu
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

CVSS3: 5.6
redhat
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

CVSS3: 4
debian
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386. ...

suse-cvrf
около 8 лет назад

Security update for gcc48

suse-cvrf
около 8 лет назад

Security update for gcc48

EPSS

Процентиль: 31%
0.00115
Низкий

4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-338