RHEL 4 : gcc (RHSA-2007:0220)

high Nessus Plugin ID 25137

Synopsis

The remote Red Hat host is missing a security update for gcc.

Description

The remote Redhat Enterprise Linux 4 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2007:0220 advisory.

The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95 GNU compilers and related support libraries.

Jrgen Weigert discovered a directory traversal flaw in fastjar. An attacker could create a malicious JAR file which, if unpacked using fastjar, could write to any files the victim had write access to.
(CVE-2006-3619)

These updated packages also fix several bugs, including:

* two debug information generator bugs

* two internal compiler errors

In addition to this, protoize.1 and unprotoize.1 manual pages have been added to the package and __cxa_get_exception_ptr@@CXXABI_1.3.1 symbol has been added into libstdc++.so.6.

For full details regarding all fixed bugs, refer to the package changelog as well as the specified list of bug reports from bugzilla.

All users of gcc should upgrade to these updated packages, which contain backported patches to resolve these issues.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL gcc package based on the guidance in RHSA-2007:0220.

See Also

http://www.nessus.org/u?9e0e677d

https://access.redhat.com/security/updates/classification/#moderate

https://bugzilla.redhat.com/show_bug.cgi?id=198912

https://bugzilla.redhat.com/show_bug.cgi?id=205919

https://bugzilla.redhat.com/show_bug.cgi?id=207277

https://bugzilla.redhat.com/show_bug.cgi?id=207303

https://bugzilla.redhat.com/show_bug.cgi?id=214353

https://bugzilla.redhat.com/show_bug.cgi?id=218377

https://access.redhat.com/errata/RHSA-2007:0220

Plugin Details

Severity: High

ID: 25137

File Name: redhat-RHSA-2007-0220.nasl

Version: 1.25

Type: local

Agent: unix

Published: 5/2/2007

Updated: 3/20/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2006-3619

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:gcc-c%2b%2b, p-cpe:/a:redhat:enterprise_linux:gcc-c%2b%2b-ppc32, p-cpe:/a:redhat:enterprise_linux:libf2c, p-cpe:/a:redhat:enterprise_linux:libgcc, p-cpe:/a:redhat:enterprise_linux:gcc, p-cpe:/a:redhat:enterprise_linux:libgcj, p-cpe:/a:redhat:enterprise_linux:libstdc%2b%2b, p-cpe:/a:redhat:enterprise_linux:gcc-g77, cpe:/o:redhat:enterprise_linux:4, p-cpe:/a:redhat:enterprise_linux:cpp, p-cpe:/a:redhat:enterprise_linux:gcc-objc, p-cpe:/a:redhat:enterprise_linux:gcc-java, p-cpe:/a:redhat:enterprise_linux:gcc-gnat, p-cpe:/a:redhat:enterprise_linux:libgnat, p-cpe:/a:redhat:enterprise_linux:libstdc%2b%2b-devel, p-cpe:/a:redhat:enterprise_linux:gcc-ppc32, p-cpe:/a:redhat:enterprise_linux:libgcj-devel, p-cpe:/a:redhat:enterprise_linux:libobjc

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 5/1/2007

Vulnerability Publication Date: 7/25/2006

Reference Information

CVE: CVE-2006-3619

RHSA: 2007:0220