openSUSE-SU-2017:2901-1: moderate: Security update for gcc48
openSUSE Security Update: Security update for gcc48 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:2901-1 Rating: moderate References: #1011348 #1022062 #1028744 #1039513 #1044016 #1050947 #988274 Cross-References: CVE-2017-11671 Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2 ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for gcc48 fixes the following issues: Security issues fixed: - A new option -fstack-clash-protection is now offered, which mitigates the stack clash type of attacks. [bnc#1039513] Future maintenance releases of packages will be built with this option. - CVE-2017-11671: Fixed rdrand/rdseed code generation issue [bsc#1050947] Bugs fixed: - Enable LFS support in 32bit libgcov.a. [bsc#1044016] - Bump libffi version in libffi.pc to 3.0.11. - Fix libffi issue for armv7l. [bsc#988274] - Properly diagnose missing -fsanitize=address support on ppc64le. [bnc#1028744] - Backport patch for PR65612. [bnc#1022062] - Fixed DR#1288. [bnc#1011348] This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2017-1223=1 - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-1223=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (i586 x86_64): cpp48-4.8.5-26.2 cpp48-debuginfo-4.8.5-26.2 gcc48-4.8.5-26.2 gcc48-ada-4.8.5-26.2 gcc48-ada-debuginfo-4.8.5-26.2 gcc48-c++-4.8.5-26.2 gcc48-c++-debuginfo-4.8.5-26.2 gcc48-debuginfo-4.8.5-26.2 gcc48-debugsource-4.8.5-26.2 gcc48-fortran-4.8.5-26.2 gcc48-fortran-debuginfo-4.8.5-26.2 gcc48-gij-4.8.5-26.2 gcc48-gij-debuginfo-4.8.5-26.2 gcc48-java-4.8.5-26.2 gcc48-java-debuginfo-4.8.5-26.2 gcc48-locale-4.8.5-26.2 gcc48-obj-c++-4.8.5-26.2 gcc48-obj-c++-debuginfo-4.8.5-26.2 gcc48-objc-4.8.5-26.2 gcc48-objc-debuginfo-4.8.5-26.2 gcc48-testresults-4.8.5-26.4 libada48-4.8.5-26.2 libada48-debuginfo-4.8.5-26.2 libasan0-4.8.5-26.2 libasan0-debuginfo-4.8.5-26.2 libffi4-gcc48-4.8.5-26.1 libffi4-gcc48-debuginfo-4.8.5-26.1 libffi48-debugsource-4.8.5-26.1 libffi48-devel-4.8.5-26.1 libgcj48-4.8.5-26.2 libgcj48-debuginfo-4.8.5-26.2 libgcj48-debugsource-4.8.5-26.2 libgcj48-devel-4.8.5-26.2 libgcj48-devel-debuginfo-4.8.5-26.2 libgcj48-jar-4.8.5-26.2 libgcj_bc1-4.8.5-26.2 libobjc4-4.8.5-26.2 libobjc4-debuginfo-4.8.5-26.2 libstdc++48-devel-4.8.5-26.2 - openSUSE Leap 42.3 (x86_64): cross-aarch64-gcc48-icecream-backend-4.8.5-26.4 cross-armv6hl-gcc48-icecream-backend-4.8.5-26.4 cross-armv7hl-gcc48-icecream-backend-4.8.5-26.4 cross-i386-gcc48-icecream-backend-4.8.5-26.4 cross-ia64-gcc48-icecream-backend-4.8.5-26.4 cross-ppc-gcc48-icecream-backend-4.8.5-26.4 cross-ppc64-gcc48-icecream-backend-4.8.5-26.4 cross-ppc64le-gcc48-icecream-backend-4.8.5-26.4 cross-s390-gcc48-icecream-backend-4.8.5-26.4 cross-s390x-gcc48-icecream-backend-4.8.5-26.4 gcc48-32bit-4.8.5-26.2 gcc48-ada-32bit-4.8.5-26.2 gcc48-fortran-32bit-4.8.5-26.2 gcc48-gij-32bit-4.8.5-26.2 gcc48-gij-debuginfo-32bit-4.8.5-26.2 gcc48-objc-32bit-4.8.5-26.2 libada48-32bit-4.8.5-26.2 libada48-32bit-debuginfo-4.8.5-26.2 libasan0-32bit-4.8.5-26.2 libasan0-32bit-debuginfo-4.8.5-26.2 libffi4-gcc48-32bit-4.8.5-26.1 libffi4-gcc48-32bit-debuginfo-4.8.5-26.1 libffi48-devel-32bit-4.8.5-26.1 libgcj48-32bit-4.8.5-26.2 libgcj48-debuginfo-32bit-4.8.5-26.2 libgcj48-devel-32bit-4.8.5-26.2 libgcj48-devel-debuginfo-32bit-4.8.5-26.2 libobjc4-32bit-4.8.5-26.2 libobjc4-32bit-debuginfo-4.8.5-26.2 libstdc++48-devel-32bit-4.8.5-26.2 - openSUSE Leap 42.3 (noarch): gcc48-info-4.8.5-26.2 libstdc++48-doc-4.8.5-26.2 - openSUSE Leap 42.2 (i586 x86_64): cpp48-4.8.5-23.3.2 cpp48-debuginfo-4.8.5-23.3.2 gcc48-4.8.5-23.3.2 gcc48-ada-4.8.5-23.3.2 gcc48-ada-debuginfo-4.8.5-23.3.2 gcc48-c++-4.8.5-23.3.2 gcc48-c++-debuginfo-4.8.5-23.3.2 gcc48-debuginfo-4.8.5-23.3.2 gcc48-debugsource-4.8.5-23.3.2 gcc48-fortran-4.8.5-23.3.2 gcc48-fortran-debuginfo-4.8.5-23.3.2 gcc48-gij-4.8.5-23.3.2 gcc48-gij-debuginfo-4.8.5-23.3.2 gcc48-java-4.8.5-23.3.2 gcc48-java-debuginfo-4.8.5-23.3.2 gcc48-locale-4.8.5-23.3.2 gcc48-obj-c++-4.8.5-23.3.2 gcc48-obj-c++-debuginfo-4.8.5-23.3.2 gcc48-objc-4.8.5-23.3.2 gcc48-objc-debuginfo-4.8.5-23.3.2 gcc48-testresults-4.8.5-23.3.4 libada48-4.8.5-23.3.2 libada48-debuginfo-4.8.5-23.3.2 libasan0-4.8.5-23.3.2 libasan0-debuginfo-4.8.5-23.3.2 libffi4-gcc48-4.8.5-23.3.1 libffi4-gcc48-debuginfo-4.8.5-23.3.1 libffi48-debugsource-4.8.5-23.3.1 libffi48-devel-4.8.5-23.3.1 libgcj48-4.8.5-23.3.2 libgcj48-debuginfo-4.8.5-23.3.2 libgcj48-debugsource-4.8.5-23.3.2 libgcj48-devel-4.8.5-23.3.2 libgcj48-devel-debuginfo-4.8.5-23.3.2 libgcj48-jar-4.8.5-23.3.2 libgcj_bc1-gcc48-4.8.5-23.3.2 libobjc4-4.8.5-23.3.2 libobjc4-debuginfo-4.8.5-23.3.2 libstdc++48-devel-4.8.5-23.3.2 - openSUSE Leap 42.2 (x86_64): cross-aarch64-gcc48-icecream-backend-4.8.5-23.3.4 cross-armv6hl-gcc48-icecream-backend-4.8.5-23.3.4 cross-armv7hl-gcc48-icecream-backend-4.8.5-23.3.4 cross-i386-gcc48-icecream-backend-4.8.5-23.3.4 cross-ia64-gcc48-icecream-backend-4.8.5-23.3.4 cross-ppc-gcc48-icecream-backend-4.8.5-23.3.4 cross-ppc64-gcc48-icecream-backend-4.8.5-23.3.4 cross-ppc64le-gcc48-icecream-backend-4.8.5-23.3.4 cross-s390-gcc48-icecream-backend-4.8.5-23.3.4 cross-s390x-gcc48-icecream-backend-4.8.5-23.3.4 gcc48-32bit-4.8.5-23.3.2 gcc48-ada-32bit-4.8.5-23.3.2 gcc48-fortran-32bit-4.8.5-23.3.2 gcc48-gij-32bit-4.8.5-23.3.2 gcc48-gij-debuginfo-32bit-4.8.5-23.3.2 gcc48-objc-32bit-4.8.5-23.3.2 libada48-32bit-4.8.5-23.3.2 libada48-32bit-debuginfo-4.8.5-23.3.2 libasan0-32bit-4.8.5-23.3.2 libasan0-32bit-debuginfo-4.8.5-23.3.2 libffi4-gcc48-32bit-4.8.5-23.3.1 libffi4-gcc48-32bit-debuginfo-4.8.5-23.3.1 libffi48-devel-32bit-4.8.5-23.3.1 libgcj48-32bit-4.8.5-23.3.2 libgcj48-debuginfo-32bit-4.8.5-23.3.2 libgcj48-devel-32bit-4.8.5-23.3.2 libgcj48-devel-debuginfo-32bit-4.8.5-23.3.2 libobjc4-32bit-4.8.5-23.3.2 libobjc4-32bit-debuginfo-4.8.5-23.3.2 libstdc++48-devel-32bit-4.8.5-23.3.2 - openSUSE Leap 42.2 (noarch): gcc48-info-4.8.5-23.3.2 libstdc++48-doc-4.8.5-23.3.2 References: https://www.suse.com/security/cve/CVE-2017-11671.html https://bugzilla.suse.com/1011348 https://bugzilla.suse.com/1022062 https://bugzilla.suse.com/1028744 https://bugzilla.suse.com/1039513 https://bugzilla.suse.com/1044016 https://bugzilla.suse.com/1050947 https://bugzilla.suse.com/988274
participants (1)
-
opensuse-security@opensuse.org