CVE-2011-4355
published 2013-03-05CVE-2011-4355: GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.36%
28.3th percentile
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gdb | < gdb 7.6-1 (bookworm) | gdb 7.6-1 (bookworm) |
| gnu | gdb | <= 7.4.1 | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
| gnu | gdb | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f7x3-c4pv-3v5r: GNU Project Debugger (GDB) before 7
ghsa_unreviewed·2022-05-17
CVE-2011-4355 [MEDIUM] GHSA-f7x3-c4pv-3v5r: GNU Project Debugger (GDB) before 7
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
OSV
CVE-2011-4355: GNU Project Debugger (GDB) before 7
osv·2013-03-05·CVSS 6.9
CVE-2011-4355 [MEDIUM] CVE-2011-4355: GNU Project Debugger (GDB) before 7
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
Red Hat
gdb: object file .debug_gdb_scripts section improper input validation
vendor_redhat·2011-04-29·CVSS 6.9
CVE-2011-4355 [MEDIUM] CWE-20 gdb: object file .debug_gdb_scripts section improper input validation
gdb: object file .debug_gdb_scripts section improper input validation
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
Package: gdb (Red Hat Enterprise Linux 4) - Will not fix
Package: gdb (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2011-4355: gdb - GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, autom...
vendor_debian·2011·CVSS 6.9
CVE-2011-4355 [MEDIUM] CVE-2011-4355: gdb - GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, autom...
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
Scope: local
bookworm: resolved (fixed in 7.6-1)
bullseye: resolved (fixed in 7.6-1)
forky: resolved (fixed in 7.6-1)
sid: resolved (fixed in 7.6-1)
trixie: resolved (fixed in 7.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4355 gdb: arbitrary code execution via .debug_gdb_scripts [fedora-all]
bugzilla·2011-11-22·CVSS 6.9
CVE-2011-4355 [MEDIUM] CVE-2011-4355 gdb: arbitrary code execution via .debug_gdb_scripts [fedora-all]
CVE-2011-4355 gdb: arbitrary code execution via .debug_gdb_scripts [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=secu
Bugzilla
CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation
bugzilla·2011-05-09·CVSS 6.9
CVE-2011-4355 [MEDIUM] CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation
CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation
It was discovered [1],[2] the the GNU Debugger (gdb) would load untrusted files from the current working directory when .debug_gdb_scripts was defined. While this was a design decision, it is an insecure one and users who do not pre-inspect untrusted files may execute arbitrary code with their privileges.
[1] http://sourceware.org/ml/gdb-patches/2011-04/msg00559.html
[2] http://sourceware.org/ml/gdb-patches/2011-05/msg00202.html
Discussion:
Created gdb tracking bugs for this issue
Affects: fedora-all [bug 756117]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0522 https://rhn.redhat.com/errata/RHSA-2013-0522.html
http://rhn.redhat.com/errata/RHSA-2013-0522.htmlhttp://sourceware.org/cgi-bin/cvsweb.cgi/~checkout~/src/gdb/NEWS?content-type=text/x-cvsweb-markup&cvsroot=srchttp://sourceware.org/ml/gdb-patches/2011-04/msg00559.htmlhttp://sourceware.org/ml/gdb-patches/2011-05/msg00202.htmlhttp://www.securitytracker.com/id/1028191http://rhn.redhat.com/errata/RHSA-2013-0522.htmlhttp://sourceware.org/cgi-bin/cvsweb.cgi/~checkout~/src/gdb/NEWS?content-type=text/x-cvsweb-markup&cvsroot=srchttp://sourceware.org/ml/gdb-patches/2011-04/msg00559.htmlhttp://sourceware.org/ml/gdb-patches/2011-05/msg00202.htmlhttp://www.securitytracker.com/id/1028191
2013-03-05
Published