Buffer overflow in The GNU Project Debugger (GDB) - CVE-2019-1010180

 

Buffer overflow in The GNU Project Debugger (GDB) - CVE-2019-1010180

Published: May 23, 2025


Vulnerability identifier: #VU109675
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1010180
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing ELF files. A remote attacker can create a specially crafted file, trick the victim into opening it with a debugger, trigger memory corruption and execute arbitrary code on the target system.


Affected software

The GNU Project Debugger (GDB)
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
crash
crash-devel
crash-debuginfo
crash-debugsource
crash-help
gdb (Red Hat package)
sys-devel/gdb

How to mitigate CVE-2019-1010180

Install updates from vendor's website.

The GNU Project Debugger (GDB) - update to 9.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
crash - update to 7.2.8-4
crash-devel - update to 7.2.8-4
crash-debuginfo - update to 7.2.8-4
crash-debugsource - update to 7.2.8-4
crash-help - update to 7.2.8-4
gdb (Red Hat package) - update to 8.2-11.el8
sys-devel/gdb - update to 9.1

External References

Related Security Bulletins