CentOS 4 : gcc (CESA-2007:0220)

low Nessus Plugin ID 67041

Synopsis

The remote CentOS host is missing one or more security updates.

Description

Updated gcc packages that fix a security issue and various bugs are now available.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95 GNU compilers and related support libraries.

Jurgen Weigert discovered a directory traversal flaw in fastjar. An attacker could create a malicious JAR file which, if unpacked using fastjar, could write to any files the victim had write access to.
(CVE-2006-3619)

These updated packages also fix several bugs, including :

* two debug information generator bugs

* two internal compiler errors

In addition to this, protoize.1 and unprotoize.1 manual pages have been added to the package and __cxa_get_exception_ptr@@CXXABI_1.3.1 symbol has been added into libstdc++.so.6.

For full details regarding all fixed bugs, refer to the package changelog as well as the specified list of bug reports from bugzilla.

All users of gcc should upgrade to these updated packages, which contain backported patches to resolve these issues.

Solution

Update the affected gcc packages.

See Also

http://www.nessus.org/u?2457cd65

Plugin Details

Severity: Low

ID: 67041

File Name: centos_RHSA-2007-0220.nasl

Version: 1.7

Type: local

Agent: unix

Published: 6/29/2013

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Low

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:centos:centos:libgcj-devel, p-cpe:/a:centos:centos:libf2c, p-cpe:/a:centos:centos:cpp, p-cpe:/a:centos:centos:libgcj, p-cpe:/a:centos:centos:gcc, p-cpe:/a:centos:centos:libobjc, p-cpe:/a:centos:centos:gcc-objc, p-cpe:/a:centos:centos:libgnat, p-cpe:/a:centos:centos:gcc-g77, p-cpe:/a:centos:centos:gcc-gnat, p-cpe:/a:centos:centos:libstdc%2b%2b-devel, p-cpe:/a:centos:centos:gcc-c%2b%2b, cpe:/o:centos:centos:4, p-cpe:/a:centos:centos:libstdc%2b%2b, p-cpe:/a:centos:centos:gcc-java, p-cpe:/a:centos:centos:libgcc

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

Patch Publication Date: 5/2/2007

Vulnerability Publication Date: 7/25/2006

Reference Information

CVE: CVE-2006-3619

RHSA: 2007:0220