PT-2006-1041 · Gnu+1 · Gnu Debugger+1
Tavis Ormandy
+3
·
Published
2006-08-31
·
Updated
2017-10-11
·
CVE-2006-4146
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
GNU Debugger (GDB) version 6.5
gdb package version 6.3.0.0
Description:
The issue is related to a buffer overflow in the debugging code of GNU Debugger (GDB), specifically in the DWARF and DWARF2 debugging code. This allows attackers to execute arbitrary code via a crafted file with a location block that contains a large number of operations. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations:
For GNU Debugger (GDB) version 6.5, consider updating to a newer version to mitigate the risk.
For gdb package version 6.3.0.0, update to a newer version to resolve the issue.
As a temporary workaround, consider restricting access to the debugging functionality until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Debugger
Red Hat