CVE-2011-4355

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/03/2013
Last modified:
11/04/2025

Description

GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:gdb:*:*:*:*:*:*:*:* 7.4.1 (including)
cpe:2.3:a:gnu:gdb:4.18:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.0.92:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.0.93:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:5.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:6.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:6.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:6.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gdb:6.2.1:*:*:*:*:*:*:*