CVE-2006-4146
GDB buffer overflow
Severity Score
5.1
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
Desbordamiento de búfer en el código de depuración (1) DWARF (dwarfread.c) y (2) DWARF2 (dwarf2read.c) en GNU Debugger (GDB) 6.5 permite a atacantes con la intervención del usuario, o a usuarios restringidos, ejecutar código de su elección mediante un archivo creado artesanalmente con un bloque de posición (DW_FORM_block) que contenga un gran número de operaciones.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-08-15 CVE Reserved
- 2006-08-31 CVE Published
- 2024-03-12 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (28)
URL | Tag | Source |
---|---|---|
http://docs.info.apple.com/article.html?artnum=304669 | X_refsource_confirm | |
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html | Mailing List | |
http://securitytracker.com/id?1017138 | Vdb Entry | |
http://support.avaya.com/elmodocs2/security/ASA-2007-253.htm | X_refsource_confirm | |
http://www.osvdb.org/28318 | Vdb Entry | |
http://www.securityfocus.com/bid/19802 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/3433 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/4283 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/3229 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10463 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=204841 | 2017-10-11 |
URL | Date | SRC |
---|---|---|
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc | 2017-10-11 | |
http://lists.apple.com/archives/security-announce/2006/Oct/msg00000.html | 2017-10-11 | |
http://secunia.com/advisories/21713 | 2017-10-11 | |
http://secunia.com/advisories/22205 | 2017-10-11 | |
http://secunia.com/advisories/22662 | 2017-10-11 | |
http://secunia.com/advisories/25098 | 2017-10-11 | |
http://secunia.com/advisories/25632 | 2017-10-11 | |
http://secunia.com/advisories/25894 | 2017-10-11 | |
http://secunia.com/advisories/25934 | 2017-10-11 | |
http://secunia.com/advisories/26909 | 2017-10-11 | |
http://secunia.com/advisories/27706 | 2017-10-11 | |
http://security.gentoo.org/glsa/glsa-200711-23.xml | 2017-10-11 | |
http://www.redhat.com/support/errata/RHSA-2007-0229.html | 2017-10-11 | |
http://www.redhat.com/support/errata/RHSA-2007-0469.html | 2017-10-11 | |
http://www.ubuntu.com/usn/usn-356-1 | 2017-10-11 | |
https://access.redhat.com/security/cve/CVE-2006-4146 | 2007-06-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=203875 | 2007-06-07 |