Use-after-free in The GNU Project Debugger (GDB) - CVE-2023-39129

 

Use-after-free in The GNU Project Debugger (GDB) - CVE-2023-39129

Published: January 29, 2024


Vulnerability identifier: #VU85873
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39129
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the add_pe_exported_sym() function in /gdb/coff-pe-read.c. A remote attacker can trick the victim to call the application on a psecially crafted file and perform a denial of service (DoS) attack.


Affected software

The GNU Project Debugger (GDB)
IBM Sterling Order Management
Robotic Process Automation for Cloud Pak
Ubuntu
openEuler
Anolis OS
Ubuntu security updates mailing list (Ubuntu package)
gdb (Ubuntu package)
gdbserver (Ubuntu package)
gdb-debuginfo
gdb-debugsource
gdb-gdbserver
gdb-headless
gdb-help
gdb
gdb-doc

How to mitigate CVE-2023-39129

Install updates from vendor's website.

Ubuntu security updates mailing list (Ubuntu package) - update to Security announcements mailing list
gdb (Ubuntu package) - addressed in versions Ubuntu Pro, 9.2-0ubuntu1~20.04.2, 12.1-0ubuntu1~22.04.2
gdbserver (Ubuntu package) - addressed in versions Ubuntu Pro, 9.2-0ubuntu1~20.04.2, 12.1-0ubuntu1~22.04.2
gdb-debuginfo - addressed in versions 9.2-6, 9.2-7, 11.1-6, 11.1-7
gdb-debugsource - addressed in versions 9.2-6, 9.2-7, 11.1-6, 11.1-7
gdb-gdbserver - addressed in versions 9.2-6, 9.2-7, 11.1-6, 11.1-7
gdb-headless - addressed in versions 9.2-6, 9.2-7, 11.1-6, 11.1-7
gdb-help - addressed in versions 9.2-6, 9.2-7, 11.1-6, 11.1-7
gdb - addressed in versions 9.2-6, 9.2-7, 11.1-6, 11.1-7
IBM Sterling Order Management - update to 10.0.2403.1
gdb-gdbserver - addressed in versions 12.1-3, 13.2-1
gdb-doc - addressed in versions 12.1-3, 13.2-1
gdb-headless - addressed in versions 12.1-3, 13.2-1
gdb - addressed in versions 12.1-3, 13.2-1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.11

External References

Related Security Bulletins