Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-11671

Опубликовано: 25 мар. 2017
Источник: redhat
CVSS3: 5.6

Описание

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5compat-gcc-295Not affected
Red Hat Enterprise Linux 5compat-gcc-296Not affected
Red Hat Enterprise Linux 5compat-gcc-32Not affected
Red Hat Enterprise Linux 5compat-gcc-34Not affected
Red Hat Enterprise Linux 5gccNot affected
Red Hat Enterprise Linux 5gcc44Not affected
Red Hat Enterprise Linux 6compat-gcc-295Not affected
Red Hat Enterprise Linux 6compat-gcc-296Not affected
Red Hat Enterprise Linux 6compat-gcc-32Not affected
Red Hat Enterprise Linux 6compat-gcc-34Not affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1475733gcc: GCC generates incorrect code for RDRAND/RDSEED intrinsics

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

CVSS3: 4
nvd
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

CVSS3: 4
debian
больше 8 лет назад

Under certain circumstances, the ix86_expand_builtin function in i386. ...

suse-cvrf
около 8 лет назад

Security update for gcc48

suse-cvrf
около 8 лет назад

Security update for gcc48

5.6 Medium

CVSS3