SUSE-SU-2018:0300-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0300-1
SUSE-SU-2018:0300-1
Summary: Security update for gcc43
Details: This update for gcc43 fixes the following issues: Security issue fixed: - CVE-2017-1000376: Don't request excutable stack from libffi. [bnc#1045091] New features: - Add support for retpolines to mitigate the Spectre Variant 2 attack. [bnc#1074621] - Add support for zero-sized VLAs and allocas with -fstack-clash-protection. [bnc#1059075] - Add support for -fstack-clash-protection to mitigate the Stack Clash attack. [bnc#1039513] Non security bugs fixed: - Fixed build of 32bit libgcov.a with LFS support. [bsc#1044016] - Fixed issue with libstdc++ functional when an exception is thrown during construction. [bsc#999596] - Fixed issue with using gcov and #pragma pack. [bsc#977654] - Fixed ICE compiling AFS modules for the s390x kernel. [bsc#938159] - Backport large file support from GCC 4.6.
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180300-1/, https://bugzilla.suse.com/1039513, https://bugzilla.suse.com/1044016, https://bugzilla.suse.com/1045091, https://bugzilla.suse.com/1059075, https://bugzilla.suse.com/1074621, https://bugzilla.suse.com/938159, https://bugzilla.suse.com/977654, https://bugzilla.suse.com/999596, https://www.suse.com/security/cve/CVE-2017-1000376
Affected packages
Package
Name: gcc43
Purl: pkg:rpm/suse/gcc43&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
