GDB DWARF Multiple Buffer Overflow Vulnerabilities
BID:19802
CVE-2006-4146 |Info
GDB DWARF Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19802 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4146 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2006 12:00AM |
| Updated: | Nov 19 2007 03:54PM |
| Credit: | Will Drewry <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SGI ProPack 3.0 SP6 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 GNU GDB 6.4 GNU GDB 6.3 GNU GDB 6.2.1 GNU GDB 6.2 GNU GDB 6.1.1 GNU GDB 6.1 GNU GDB 6.0 Gentoo Linux Avaya SES 3.1.1 Avaya EMMC 0 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya CCS 3.1.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.3 Apple Xcode 2.3 Apple Xcode 2.2 |
| Not Vulnerable: |
Apple Xcode 2.4.1 |
Discussion
GDB DWARF Multiple Buffer Overflow Vulnerabilities
GDB is prone to multiple buffer-overflow vulnerabilities because of insufficient bounds-checking when handling DWARF and DWARF2 data.
Attackers could leverage this issue to run arbitrary code outside of a restricted environment; this may lead to privilege escalation.
GDB is prone to multiple buffer-overflow vulnerabilities because of insufficient bounds-checking when handling DWARF and DWARF2 data.
Attackers could leverage this issue to run arbitrary code outside of a restricted environment; this may lead to privilege escalation.
Exploit / POC
GDB DWARF Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
GDB DWARF Multiple Buffer Overflow Vulnerabilities
Solution:
Please see the referenced advisories for more information.
SGI ProPack 3.0 SP6
GNU GDB 6.3
GNU GDB 6.4
Solution:
Please see the referenced advisories for more information.
SGI ProPack 3.0 SP6
-
SGI Patch 10421
ftp://oss.sgi.com/projects/sgi_propack/download/
GNU GDB 6.3
-
Ubuntu gdb_6.3-5ubuntu1.2_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2_a md64.deb -
Ubuntu gdb_6.3-5ubuntu1.2_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2_i 386.deb -
Ubuntu gdb_6.3-5ubuntu1.2_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-5ubuntu1.2_p owerpc.deb -
Ubuntu gdb_6.3-6ubuntu2.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_a md64.deb -
Ubuntu gdb_6.3-6ubuntu2.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_i 386.deb -
Ubuntu gdb_6.3-6ubuntu2.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_p owerpc.deb -
Ubuntu gdb_6.3-6ubuntu2.1_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.3-6ubuntu2.1_s parc.deb
GNU GDB 6.4
-
Ubuntu gdb_6.4-1ubuntu5.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_a md64.deb -
Ubuntu gdb_6.4-1ubuntu5.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_i 386.deb -
Ubuntu gdb_6.4-1ubuntu5.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_p owerpc.deb -
Ubuntu gdb_6.4-1ubuntu5.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/g/gdb/gdb_6.4-1ubuntu5.1_s parc.deb
References
GDB DWARF Multiple Buffer Overflow Vulnerabilities
References:
References:
- Bugzilla Bug 204845 (Redhat)
- GDB Homepage (GNU)
- ASA-2007-253 gdb security and bug fix update (RHSA-2007-0229) (Avaya)
- ASA-2007-308 gdb security and bug fix update (RHSA-2007-0469) (Avaya)
- RHSA-2007:0229 gdb security and bug fix update (Red Hat)
- RHSA-2007:0469-2 gdb security and bug fix update (Red Hat)