UBUNTU-CVE-2011-4355

Source
https://ubuntu.com/security/CVE-2011-4355
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-4355.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2011-4355
Related
Published
2013-03-05T21:38:00Z
Modified
2013-03-05T21:38:00Z
Summary
[none]
Details

GNU Project Debugger (GDB) before 7.5, when .debuggdbscripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.

References

Affected packages

Ubuntu:14.04:LTS / gdb

Package

Name
gdb
Purl
pkg:deb/ubuntu/gdb?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.7-0ubuntu3.1

Affected versions

7.*

7.6.1-0ubuntu3
7.6.1-1ubuntu1
7.6.50.20131218-0ubuntu1
7.7-0ubuntu1
7.7-0ubuntu2
7.7-0ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "7.7-0ubuntu3.1",
            "binary_name": "gdb"
        },
        {
            "binary_version": "7.7-0ubuntu3.1",
            "binary_name": "gdb-minimal"
        },
        {
            "binary_version": "7.7-0ubuntu3.1",
            "binary_name": "gdb-multiarch"
        },
        {
            "binary_version": "7.7-0ubuntu3.1",
            "binary_name": "gdb-source"
        },
        {
            "binary_version": "7.7-0ubuntu3.1",
            "binary_name": "gdb64"
        },
        {
            "binary_version": "7.7-0ubuntu3.1",
            "binary_name": "gdbserver"
        }
    ]
}