SUSE-SU-2017:0379-1
Dashboard / Vulnerabilities / SUSE-SU-2017:0379-1
SUSE-SU-2017:0379-1
Summary: Security update for gcc48
Details: This update for gcc48 to version 4.8.5 fixes several issues. This security issue was fixed: - CVE-2015-5276: The std::random_device class in libstdc++ did not properly handle short reads from blocking sources, which made it easier for context-dependent attackers to predict the random values via unspecified vectors (bsc#945842). These non-security issues were fixed: - Provide missing libasan0-32bit and other multilibs via the updated product description [bsc#951644] - Fixed libffi issue for armv7l [bsc#988274] - Fixed libffi issue for armv7l [bsc#988274] - Fixed a kernel miscompile on aarch64 [bnc#981311] - Fixed a ppc64le ICE. [bnc#976627] - Fixed issue with using gcov and #pragma pack [bsc#977654] - Fixed samba build on AARCH64 [bsc#970009] - Fixed HTM builtins on powerpc [bsc#955382] - Fixed build of SLOF [bsc#949000] - Fixed libffi issues on aarch64 [bsc#948168] - Fixed no_instrument_function attribute handling on PPC64 with -mprofile-kernel [bsc#947791] - Fixed bogus integer overflow in constant expression [bsc#934689] - Fixed ICE with atomics on aarch64 [bsc#930176] - Fixed -imacros bug [bsc#917169] - Fixed incorrect -Warray-bounds warnings [bsc#919274] - Updated -mhotpatch for s390x [bsc#924525] - Fixed ppc64le issue with doubleword vector extract [bsc#924687] - Fixed reload issue on S390. - Keep functions leaf when they are instrumented for profiling on s390[x] [bsc#899871] - Avoid accessing invalid memory when passing aggregates by value [bsc#922534] - Rework of the memory allocator for C++ exceptions used in OOM situations [bsc#889990]
References: https://www.suse.com/support/update/announcement/2017/suse-su-20170379-1/, https://bugzilla.suse.com/1011348, https://bugzilla.suse.com/889990, https://bugzilla.suse.com/899871, https://bugzilla.suse.com/917169, https://bugzilla.suse.com/919274, https://bugzilla.suse.com/922534, https://bugzilla.suse.com/924525, https://bugzilla.suse.com/924687, https://bugzilla.suse.com/930176, https://bugzilla.suse.com/934689, https://bugzilla.suse.com/945842, https://bugzilla.suse.com/947772, https://bugzilla.suse.com/947791, https://bugzilla.suse.com/948168, https://bugzilla.suse.com/949000, https://bugzilla.suse.com/951644, https://bugzilla.suse.com/955382, https://bugzilla.suse.com/970009, https://bugzilla.suse.com/976627, https://bugzilla.suse.com/977654, https://bugzilla.suse.com/981311, https://bugzilla.suse.com/988274, https://www.suse.com/security/cve/CVE-2015-5276
Affected packages
Package
Name: gcc48
Purl: pkg:rpm/suse/gcc48&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
