CVE-2011-4355
CVE-2011-4355
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://rhn.redhat.com/errata/RHSA-2013-0522.htmlhttp://sourceware.org/cgi-bin/cvsweb.cgi/~checkout~/src/gdb/NEWS?content-type=text/x-cvsweb-markup&cvsroot=srchttp://sourceware.org/ml/gdb-patches/2011-04/msg00559.htmlhttp://sourceware.org/ml/gdb-patches/2011-05/msg00202.htmlhttp://www.securitytracker.com/id/1028191