|
 |
|
GDB Integer Overflow and Insecure Initialisation File Handling
|
|
|
|
|
Secunia Advisory:
|
SA15449
|
|
|
Release Date:
|
2005-05-23
|
|
Last Update:
|
2005-05-26
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
Privilege escalation
|
|
Where:
|
Local system
|
|
Solution Status:
|
Unpatched
|
|
| Software: | GDB 6.x
|
| | CVE reference: | CVE-2005-1704 (Secunia mirror) CVE-2005-1705 (Secunia mirror)
|
|
|
This advisory is currently marked as unpatched! - Companies can be alerted when a patch is released! |
|
|
Description: Tavis Ormandy has reported two vulnerabilities in GDB, which potentially can be exploited by malicious, local users to gain escalated privileges.
1) By default, the .gdbinit file is read from the current working directory, which can be exploited to execute arbitrary code with escalated privileges by tricking a user into running GDB in a directory containing a malicious .gdbinit file.
2) An integer overflow in the BFD library can be exploited to cause a heap-based buffer overflow by tricking a user into loading a specially crafted binary in GDB.
Solution: Don't open untrusted files in GDB or run it from untrusted directories.
Provided and/or discovered by: Tavis Ormandy, Gentoo Linux Security Audit Team.
Changelog: 2005-05-26: Added CVE references.
Original Advisory: Gentoo:
http://security.gentoo.org/glsa/glsa-200505-15.xml
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
1 Related Secunia Security Advisories
|
|
|
1. GDB "DWARF" Buffer Overflow Vulnerabilities
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|