CVE-2019-1010180 describes a buffer overflow vulnerability in all versions of GNU GDB, as well as GNU Leap and OpenSUSE GDB/Leap. This flaw, triggered by opening a specially crafted ELF file for debugging, allows for denial of service, memory disclosure, and potentially remote code execution. With a CVSS score of 7.8 (High), it requires user interaction (opening the ELF) but is otherwise low complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and the vulnerability remains unfixed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.1CPE matchmatch criteria | cpe:2.3:a:gnu:gdb:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-1010180
Sep 8, 2020gdb: buffer overflow while opening an ELF for debugging leads to Dos, information dislosure and code execution
Aug 13, 2019GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
Jul 9, 2019