PT-2017-12164 · Gnu+4 · Gcc+4

Todd Eisenberger

·

Publicado

2017-07-26

·

Atualizado

2022-12-08

·

CVE-2017-11671

CVSS v3.1

4.0

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNU Compiler Collection (GCC) versions 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4
Description The issue arises in the ix86 expand builtin function in i386.c, where under certain circumstances, it generates instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read. This could potentially cause failures of these instructions to go unreported, leading to less randomness in random number generation.
Recommendations For GNU Compiler Collection (GCC) version 4.6, update to a version after 4.6. For GNU Compiler Collection (GCC) version 4.7, update to a version after 4.7. For GNU Compiler Collection (GCC) version 4.8, update to a version after 4.8. For GNU Compiler Collection (GCC) version 4.9, update to a version after 4.9. For GNU Compiler Collection (GCC) version 5 before 5.5, update to version 5.5 or later. For GNU Compiler Collection (GCC) version 6 before 6.4, update to version 6.4 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2018_0849
CVE-2017-11671
RHSA-2018:0849
RHSA-2018_0849
SUSE-SU-2017:2380-1
SUSE-SU-2017:2526-1
SUSE-SU-2017_2380-1
SUSE-SU-2017_2526-1
USN-5770-1

Produtos afetados

Centos
Gcc
Red Hat
Suse
Ubuntu