CVE-2011-4355

Description

GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.163

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2013:0522) Moderate: gdb security and bug fix update gdb-7.2-60.el6.i686.rpmLinux
(RHSA-2013:0522) Moderate: gdb security and bug fix update gdb-7.2-60.el6.x86_64.rpmLinux
(RHSA-2013:0522) Moderate: gdb security and bug fix update gdb-gdbserver-7.2-60.el6.i686.rpmLinux
(RHSA-2013:0522) Moderate: gdb security and bug fix update gdb-gdbserver-7.2-60.el6.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234