CVE-2011-4355 Information

Description

GNU Project Debugger (GDB) before 7.5 when .debug_gdb_scripts is defined automatically loads certain files from the current working directory which allows local users to gain privileges via crafted files such as Python scripts.

Reference

http://rhn.redhat.com/errata/RHSA-2013-0522.html http://sourceware.org/cgi-bin/cvsweb.cgi/checkout/src/gdb/NEWS?content-type=text/x-cvsweb-markup&cvsroot=src http://sourceware.org/ml/gdb-patches/2011-04/msg00559.html http://sourceware.org/ml/gdb-patches/2011-05/msg00202.html http://www.securitytracker.com/id/1028191

Share on: