CVE-2005-1705
published 2005-05-24CVE-2005-1705: gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the…
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.44%
35.2th percentile
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gdb | < gdb 6.3-6 (bookworm) | gdb 6.3-6 (bookworm) |
| gnu | gdb | <= 6.3 | — |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jcm-wwpx-vpr3: gdb before 6
ghsa_unreviewed·2022-05-01
CVE-2005-1705 [HIGH] GHSA-5jcm-wwpx-vpr3: gdb before 6
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
OSV
CVE-2005-1705: gdb before 6
osv·2005-05-24·CVSS 7.2
CVE-2005-1705 [HIGH] CVE-2005-1705: gdb before 6
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2005-05-27
CVE-2005-1704 gdb vulnerabilities
Title: gdb vulnerabilities
Summary: gdb vulnerabilities
Tavis Ormandy found an integer overflow in the GNU debugger. By
tricking an user into merely load a specially crafted executable, an
attacker could exploit this to execute arbitrary code with the
privileges of the user running gdb. However, loading untrusted
binaries without actually executing them is rather uncommon, so the
risk of this flaw is low. (CAN-2005-1704)
Tavis Ormandy also discovered that gdb loads and executes the file
".gdbinit" in the current directory even if the file belongs to a
different user. By tricking an user into run gdb in a directory with a
malicious .gdbinit file, a local attacker could exploit this to run
arbitrary commands with the privileges of the user invoking gdb.
(CAN-2005-1705)
Instructions: In g
Red Hat
security flaw
vendor_redhat·2005-05-25·CVSS 7.2
CVE-2005-1705 [HIGH] security flaw
security flaw
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-1705: gdb - gdb before 6.3 searches the current working directory to load the .gdbinit confi...
vendor_debian·2005·CVSS 7.2
CVE-2005-1705 [HIGH] CVE-2005-1705: gdb - gdb before 6.3 searches the current working directory to load the .gdbinit confi...
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
Scope: local
bookworm: resolved (fixed in 6.3-6)
bullseye: resolved (fixed in 6.3-6)
forky: resolved (fixed in 6.3-6)
sid: resolved (fixed in 6.3-6)
trixie: resolved (fixed in 6.3-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-1705 security flaw
bugzilla·2018-08-16·CVSS 7.2
CVE-2005-1705 [HIGH] CVE-2005-1705 security flaw
CVE-2005-1705 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2008-4865 valgrind: .valgrindrc loaded from untrusted locations
bugzilla·2008-11-03·CVSS 7.2
CVE-2008-4865 [HIGH] CVE-2008-4865 valgrind: .valgrindrc loaded from untrusted locations
CVE-2008-4865 valgrind: .valgrindrc loaded from untrusted locations
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4865 to the following vulnerability:
Untrusted search path vulnerability in valgrind allows local users to
execute arbitrary programs via a Trojan horse .valgrindrc file in the
current working directory, as demonstrated using a malicious
--db-command options. NOTE: the severity of this issue has been
disputed, but CVE is including this issue because execution of a
program from an untrusted directory is a common scenario.
References:
http://www.openwall.com/lists/oss-security/2008/10/27/4
Discussion:
As a side note:
Similar issue was reported in the past for gdb and its handling of .gdbinit file and was assigned CVE id CVE-2005-1705:
http://bugs.gent
http://bugs.gentoo.org/show_bug.cgi?id=88398http://secunia.com/advisories/17072http://secunia.com/advisories/17356http://secunia.com/advisories/18506http://security.gentoo.org/glsa/glsa-200505-15.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2006-015.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:095http://www.redhat.com/support/errata/RHSA-2005-709.htmlhttp://www.redhat.com/support/errata/RHSA-2005-801.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11072http://bugs.gentoo.org/show_bug.cgi?id=88398http://secunia.com/advisories/17072http://secunia.com/advisories/17356http://secunia.com/advisories/18506http://security.gentoo.org/glsa/glsa-200505-15.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2006-015.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:095http://www.redhat.com/support/errata/RHSA-2005-709.htmlhttp://www.redhat.com/support/errata/RHSA-2005-801.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11072
2005-05-24
Published