Buffer overflow in The GNU Project Debugger (GDB) - CVE-2019-1010180
Published: May 23, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing ELF files. A remote attacker can create a specially crafted file, trick the victim into opening it with a debugger, trigger memory corruption and execute arbitrary code on the target system.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
crash
crash-devel
crash-debuginfo
crash-debugsource
crash-help
gdb (Red Hat package)
sys-devel/gdb
How to mitigate CVE-2019-1010180
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
crash - update to 7.2.8-4
crash-devel - update to 7.2.8-4
crash-debuginfo - update to 7.2.8-4
crash-debugsource - update to 7.2.8-4
crash-help - update to 7.2.8-4
gdb (Red Hat package) - update to 8.2-11.el8
sys-devel/gdb - update to 9.1
External References
- https://sourceware.org/bugzilla/show_bug.cgi?id=23657
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00028.html
- https://security.gentoo.org/glsa/202003-31