Description
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
CVSS vector
AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-f7x3-c4pv-3v5r: GNU Project Debugger (GDB) before 7↗2022-05-17 ▶ OSVCVE-2011-4355: GNU Project Debugger (GDB) before 7↗2013-03-05 ▶ CVEListCVE-2011-4355: GNU Project Debugger (GDB) before 7↗2013-03-04 ▶ 📋Vendor Advisories
2Red Hatgdb: object file .debug_gdb_scripts section improper input validation↗2011-04-29 ▶ DebianCVE-2011-4355: gdb - GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, autom...↗2011 ▶ 💬Community
2BugzillaCVE-2011-4355 gdb: arbitrary code execution via .debug_gdb_scripts [fedora-all]↗2011-11-22 ▶ BugzillaCVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation↗2011-05-09 ▶