Gnu · Gnu Debugger · CVE-2006-4146
Name of the Vulnerable Software and Affected Versions:
GNU Debugger (GDB) version 6.5
gdb package version 6.3.0.0
Description:
The issue is related to a buffer overflow in the debugging code of GNU Debugger (GDB), specifically in the DWARF and DWARF2 debugging code. This allows attackers to execute arbitrary code via a crafted file with a location block that contains a large number of operations. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations:
For GNU Debugger (GDB) version 6.5, consider updating to a newer version to mitigate the risk.
For gdb package version 6.3.0.0, update to a newer version to resolve the issue.
As a temporary workaround, consider restricting access to the debugging functionality until a patch is available.