{"affected":[{"ecosystem_specific":{"binaries":[{"cpp48":"4.8.5-5.3.1","gcc48":"4.8.5-5.3.1","gcc48-32bit":"4.8.5-5.3.1","gcc48-c++":"4.8.5-5.3.1","gcc48-fortran":"4.8.5-5.3.1","gcc48-fortran-32bit":"4.8.5-5.3.1","gcc48-info":"4.8.5-5.3.1","gcc48-locale":"4.8.5-5.3.1","libasan0":"4.8.5-5.3.1","libasan0-32bit":"4.8.5-5.3.1","libstdc++48-devel":"4.8.5-5.3.1","libstdc++48-devel-32bit":"4.8.5-5.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"gcc48","purl":"pkg:rpm/suse/gcc48&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.8.5-5.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for gcc48 fixes the following issues:\n\nSecurity issues fixed:\n\n- A new option -fstack-clash-protection is now offered, which mitigates the stack clash type of attacks. [bnc#1039513]\n- CVE-2017-11671: Fixed rdrand/rdseed code generation issue [bsc#1050947]\n\nBugs fixed:\n\n- Enable LFS support in 32bit libgcov.a.  [bsc#1044016]\n- Bump libffi version in libffi.pc to 3.0.11.\n- Properly diagnose missing -fsanitize=address support on ppc64le.  [bsc#1028744]\n- Backport patch for PR65612. [bsc#1022062]\n\n","id":"SUSE-SU-2017:2380-1","modified":"2017-09-06T12:32:12Z","published":"2017-09-06T12:32:12Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20172380-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1011348"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022062"},{"type":"REPORT","url":"https://bugzilla.suse.com/1028744"},{"type":"REPORT","url":"https://bugzilla.suse.com/1039513"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044016"},{"type":"REPORT","url":"https://bugzilla.suse.com/1050947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11671"}],"related":["CVE-2017-11671"],"summary":"Security update for gcc48","upstream":["CVE-2017-11671"]}