CVE-2006-4146
published 2006-08-31CVE-2006-4146: Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or…
PriorityP423medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.23%
86.8th percentile
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gdb | < gdb 7.3-1 (bookworm) | gdb 7.3-1 (bookworm) |
| gnu | gdb | — | — |
| gnu | gdb | >= 0 < 7.3-1 | 7.3-1 |
| gnu | gdb | >= 0 < 7.3-1 | 7.3-1 |
| gnu | gdb | >= 0 < 7.3-1 | 7.3-1 |
| gnu | gdb | >= 0 < 7.3-1 | 7.3-1 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gdb vulnerability
vendor_ubuntu·2006-10-02
CVE-2006-4146 gdb vulnerability
Title: gdb vulnerability
Summary: gdb vulnerability
Will Drewry, of the Google Security Team, discovered buffer overflows
in GDB's DWARF processing. This would allow an attacker to execute
arbitrary code with user privileges by tricking the user into using
GDB to load an executable that contained malicious debugging
information.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
GDB buffer overflow
vendor_redhat·2006-08-31·CVSS 5.1
CVE-2006-4146 [MEDIUM] GDB buffer overflow
GDB buffer overflow
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
Statement: Red Hat Enterprise Linux 5 was not vulnerable to this issue as it contained a backported patch.
Debian
CVE-2006-4146: gdb - Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) deb...
vendor_debian·2006·CVSS 5.1
CVE-2006-4146 [MEDIUM] CVE-2006-4146: gdb - Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) deb...
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
Scope: local
bookworm: resolved (fixed in 7.3-1)
bullseye: resolved (fixed in 7.3-1)
forky: resolved (fixed in 7.3-1)
sid: resolved (fixed in 7.3-1)
trixie: resolved (fixed in 7.3-1)
GHSA
GHSA-63cf-4m5h-x542: Buffer overflow in the (1) DWARF (dwarfread
ghsa_unreviewed·2022-05-03
CVE-2006-4146 [MEDIUM] CWE-119 GHSA-63cf-4m5h-x542: Buffer overflow in the (1) DWARF (dwarfread
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
OSV
CVE-2006-4146: Buffer overflow in the (1) DWARF (dwarfread
osv·2006-08-31·CVSS 5.1
CVE-2006-4146 [MEDIUM] CVE-2006-4146: Buffer overflow in the (1) DWARF (dwarfread
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4146 GDB buffer overflow
bugzilla·2007-03-29·CVSS 5.1
CVE-2006-4146 [MEDIUM] CVE-2006-4146 GDB buffer overflow
CVE-2006-4146 GDB buffer overflow
Cloned bug for RHEL3
+++ This bug was initially created as a clone of Bug #204841 +++
Will Drewry of the Google Security Team discovered multiple buffer overflows in
GDB's DWARF handling code. His advisory is below:
The GNU Debugger (GDB) Multiple Vulnerabilities
Summary
Multiple vulnerabilities have been discovered in the GNU debugger that allow
for the execution of arbitrary code.
Background
GDB is the GNU Project Debugger. It is described on its project page
[http://www.gnu.org/software/gdb/] as allowing "you to see what is going on
`inside' another program while it executes -- or what another program was doing
at the moment it crashed."
DWARF is a information format standard used to represent debugging information
for a specific binary. While
Bugzilla
CVE-2006-4146 GDB buffer overflow
bugzilla·2006-08-24·CVSS 5.1
CVE-2006-4146 [MEDIUM] CVE-2006-4146 GDB buffer overflow
CVE-2006-4146 GDB buffer overflow
From: "Will Drewry"
Subject: Multiple vulnerabilities in GDB
To: [email protected], [email protected], [email protected]
Cc: [email protected], [email protected]
Date: Tue, 15 Aug 2006 18:59:33 +0100
Reply-To: [email protected]
Hi GDB maintainers (et. al.) -
I'm mailing to inform you that I've run across some exploitable
vulnerabilities in GDB. I've included a simple patch along with
a proof of concept in the advisory below.
The GNU Debugger (GDB) Multiple Vulnerabilities
Summary
Multiple vulnerabilities have been discovered in the GNU debugger that allow
for the execution of arbitrary code.
Background
GDB is the GNU Project Debugger. It is described on its project page
[http://www.gnu.org/software/gdb/] as allowing "you to see what is going on
`insi
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://docs.info.apple.com/article.html?artnum=304669http://lists.apple.com/archives/security-announce/2006/Oct/msg00000.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://secunia.com/advisories/21713http://secunia.com/advisories/22205http://secunia.com/advisories/22662http://secunia.com/advisories/25098http://secunia.com/advisories/25632http://secunia.com/advisories/25894http://secunia.com/advisories/25934http://secunia.com/advisories/26909http://secunia.com/advisories/27706http://security.gentoo.org/glsa/glsa-200711-23.xmlhttp://securitytracker.com/id?1017138http://support.avaya.com/elmodocs2/security/ASA-2007-253.htmhttp://www.osvdb.org/28318http://www.redhat.com/support/errata/RHSA-2007-0229.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0469.htmlhttp://www.securityfocus.com/bid/19802http://www.ubuntu.com/usn/usn-356-1http://www.vupen.com/english/advisories/2006/3433http://www.vupen.com/english/advisories/2006/4283http://www.vupen.com/english/advisories/2007/3229https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=204841https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10463ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://docs.info.apple.com/article.html?artnum=304669http://lists.apple.com/archives/security-announce/2006/Oct/msg00000.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://secunia.com/advisories/21713http://secunia.com/advisories/22205http://secunia.com/advisories/22662http://secunia.com/advisories/25098http://secunia.com/advisories/25632http://secunia.com/advisories/25894http://secunia.com/advisories/25934http://secunia.com/advisories/26909http://secunia.com/advisories/27706http://security.gentoo.org/glsa/glsa-200711-23.xmlhttp://securitytracker.com/id?1017138http://support.avaya.com/elmodocs2/security/ASA-2007-253.htmhttp://www.osvdb.org/28318http://www.redhat.com/support/errata/RHSA-2007-0229.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0469.htmlhttp://www.securityfocus.com/bid/19802http://www.ubuntu.com/usn/usn-356-1http://www.vupen.com/english/advisories/2006/3433http://www.vupen.com/english/advisories/2006/4283http://www.vupen.com/english/advisories/2007/3229https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=204841https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10463
2006-08-31
Published