RHSA-2007:0220: Moderate: gcc security and bug fix update
The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95GNU compilers and related support libraries.Jürgen Weigert discovered a directory traversal flaw in fastjar. Anattacker could create a malicious JAR file which, if unpacked usingfastjar, could write to any files the victim had write access to.(CVE-2006-3619)These updated packages also fix several bugs, including: two debug information generator bugs two internal compiler errors In addition to this, protoize.1 and unprotoize.1 manual pages have beenadded to the package and cxagetexceptionptr@@CXXABI1.3.1 symbol hasbeen added into libstdc++.so.6.For full details regarding all fixed bugs, refer to the package changelogas well as the specified list of bug reports from bugzilla.All users of gcc should upgrade to these updated packages, which containbackported patches to resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2007:0220?
The severity of RHSA-2007:0220 is classified as critical due to the directory traversal flaw in fastjar.
How do I fix RHSA-2007:0220?
To fix RHSA-2007:0220, update the gcc packages to the latest version provided by your operating system vendor.
What vulnerabilities are addressed in RHSA-2007:0220?
RHSA-2007:0220 addresses a directory traversal flaw in the fastjar tool included in the gcc packages.
Who discovered the vulnerability noted in RHSA-2007:0220?
The vulnerability in RHSA-2007:0220 was discovered by Jürgen Weigert.
What is the risk of not addressing RHSA-2007:0220?
Not addressing RHSA-2007:0220 could allow attackers to exploit the directory traversal flaw to gain unauthorized access to files on the system.