PT-2006-1041 · Gnu+1 · Gnu Debugger+1

Tavis Ormandy

+3

·

Published

2006-08-31

·

Updated

2017-10-11

·

CVE-2006-4146

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: GNU Debugger (GDB) version 6.5 gdb package version 6.3.0.0
Description: The issue is related to a buffer overflow in the debugging code of GNU Debugger (GDB), specifically in the DWARF and DWARF2 debugging code. This allows attackers to execute arbitrary code via a crafted file with a location block that contains a large number of operations. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations: For GNU Debugger (GDB) version 6.5, consider updating to a newer version to mitigate the risk. For gdb package version 6.3.0.0, update to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the debugging functionality until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07208
CVE-2006-4146
RHSA-2007:0229
RHSA-2007:0469
RHSA-2007_0229

Affected Products

Gnu Debugger
Red Hat