GLSA-200505-15 : gdb: Multiple vulnerabilities
High Nessus Plugin ID 18379
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200505-15 (gdb: Multiple vulnerabilities)
Tavis Ormandy of the Gentoo Linux Security Audit Team discovered an integer overflow in the BFD library, resulting in a heap overflow. A review also showed that by default, gdb insecurely sources initialisation files from the working directory.
Successful exploitation would result in the execution of arbitrary code on loading a specially crafted object file or the execution of arbitrary commands.
There is no known workaround at this time.
SolutionAll gdb users should upgrade to the latest stable version:
# emerge --sync # emerge --ask --oneshot --verbose '>=sys-devel/gdb-6.3-r3'