Heap-based buffer overflow in The GNU Project Debugger (GDB) - CVE-2023-39130

 

Heap-based buffer overflow in The GNU Project Debugger (GDB) - CVE-2023-39130

Published: January 29, 2024


Vulnerability identifier: #VU85876
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39130
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the pe_as16() function in /gdb/coff-pe-read.c. A remote attacker can trick the victim to run the debugger on a specially crafted file, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.


Affected software

The GNU Project Debugger (GDB)
Robotic Process Automation for Cloud Pak
Ubuntu
openEuler
Anolis OS
Ubuntu security updates mailing list (Ubuntu package)
gdb (Ubuntu package)
gdbserver (Ubuntu package)
gdb-debuginfo
gdb-gdbserver
gdb-help
gdb
gdb-headless
gdb-debugsource
gdb-doc

How to mitigate CVE-2023-39130

Install updates from vendor's website.

Ubuntu security updates mailing list (Ubuntu package) - update to Security announcements mailing list
gdb (Ubuntu package) - addressed in versions Ubuntu Pro, 9.2-0ubuntu1~20.04.2, 12.1-0ubuntu1~22.04.2
gdbserver (Ubuntu package) - addressed in versions Ubuntu Pro, 9.2-0ubuntu1~20.04.2, 12.1-0ubuntu1~22.04.2
gdb-debuginfo - addressed in versions 9.2-7, 11.1-7, 11.1-8
gdb-gdbserver - addressed in versions 9.2-7, 11.1-7, 11.1-8
gdb-help - addressed in versions 9.2-7, 11.1-7, 11.1-8
gdb - addressed in versions 9.2-7, 11.1-7, 11.1-8
gdb-headless - addressed in versions 9.2-7, 11.1-7, 11.1-8
gdb-debugsource - addressed in versions 9.2-7, 11.1-7, 11.1-8
gdb-doc - addressed in versions 12.1-3, 13.2-1
gdb-gdbserver - addressed in versions 12.1-3, 13.2-1
gdb-headless - addressed in versions 12.1-3, 13.2-1
gdb - addressed in versions 12.1-3, 13.2-1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.11

External References

Related Security Bulletins