CVE-2011-4355

Severity
6.9MEDIUM
EPSS
0.2%
top 62.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 5
Latest updateMay 17

Description

GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

Debiangdb< 7.6-1+3
NVDgnu/gdb7.4.1+28

🔴Vulnerability Details

3
GHSA
GHSA-f7x3-c4pv-3v5r: GNU Project Debugger (GDB) before 72022-05-17
OSV
CVE-2011-4355: GNU Project Debugger (GDB) before 72013-03-05
CVEList
CVE-2011-4355: GNU Project Debugger (GDB) before 72013-03-04

📋Vendor Advisories

2
Red Hat
gdb: object file .debug_gdb_scripts section improper input validation2011-04-29
Debian
CVE-2011-4355: gdb - GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, autom...2011

💬Community

2
Bugzilla
CVE-2011-4355 gdb: arbitrary code execution via .debug_gdb_scripts [fedora-all]2011-11-22
Bugzilla
CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation2011-05-09
CVE-2011-4355 (MEDIUM CVSS 6.9) | GNU Project Debugger (GDB) before 7 | cvebase.io