Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635544 (CVE-2017-9778) - sys-devel/gdb: Denial of Service
Summary: sys-devel/gdb: Denial of Service
Status: RESOLVED WONTFIX
Alias: CVE-2017-9778
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-27 00:03 UTC by GLSAMaker/CVETool Bot
Modified: 2018-04-08 21:25 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-10-27 00:03:24 UTC
CVE-2017-9778 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9778):
  GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field
  in a DWARF section. A malformed section in an ELF binary or a core file can
  cause GDB to repeatedly allocate memory until a process limit is reached.
  This can, for example, impede efforts to analyze malware with GDB.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-10-27 00:04:32 UTC
@Maintainers 8.0.1 is already in tree, call for stabilization when ready please.

Thank you
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-04-08 21:25:17 UTC
Issue is extremely minor and no upstream patch available addressing the issue.  The concern here could be malware that causes a crash when attempts to debug it are made.