RHSA-2010:0039: Moderate and gcc4 security update
63
This update fixes the following bug:
* if multiple "-fno-builtin-*" options were specified on the command line (for example, "-fno-builtin-
iswalpha -fno-builtin-iswalnum") only the last option was honored (in the example, -fno-builtin-
iswalnum). With this update, joined switches are no longer pruned, ensuring all such options are
honored, as expected. (
BZ#526421
397
)
Users are advised to install this gcc update, which applies this fix.
1.58.2. RHSA-2010:0039: Moderate and gcc4 security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2010:0039
398
Updated gcc and gcc4 packages that fix one security issue are now available for Red Hat Enterprise
Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The gcc and gcc4 packages include, among others, C, C++, and Java GNU compilers and related
support libraries. libgcj contains a copy of GNU Libtool's libltdl library.
A flaw was found in the way GNU Libtool's libltdl library looked for libraries to load. It was possible
for libltdl to load a malicious library from the current working directory. In certain configurations, if a
local attacker is able to trick a local user into running a Java application (which uses a function to load
native libraries, such as System.loadLibrary) from within an attacker-controlled directory containing a
malicious library or module, the attacker could possibly execute arbitrary code with the privileges of
the user running the Java application. (
CVE-2009-3736
399
)
All gcc and gcc4 users should upgrade to these updated packages, which contain a backported patch
to correct this issue. All running Java applications using libgcj must be restarted for this update to take
effect.
1.58.3. RHBA-2010:0232: bug fix update
A gcc update that resolves several compiler bugs is now available.
The gcc packages include C, C++, Java, Fortran, Objective C, and Ada 95 GNU compilers, along with
related support libraries.
This update applies the following bug fixes:
* when compiling a debug version of a C++ program, it was possible for gcc to lose debug information
for some local variables in C++ constructors or destructors. This was because gcc incorrectly released
information on abstract functions (specifically, contents of the DECL_INITIAL() function), which
are needed for creating debug information. With this release, nodes containing abstract functions
397
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=526421
399
https://www.redhat.com/security/data/cve/CVE-2009-3736.html
Содержание ENTERPRISE LINUX 5.5 - S 2010
Страница 10: ...x ...
Страница 308: ...298 ...
Страница 310: ...300 ...
Страница 468: ...458 ...
Страница 470: ...460 ...