SciLinux: CVE-2006-4146 SL3,x i386/x86_64
Summary
Date: Fri, 15 Jun 2007 17:33:06 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for on SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Low: gdb security and bug fix updateIssue date: 2007-06-11CVE Names: CVE-2006-4146Various buffer overflows and underflows were found in the DWARF expressioncomputation stack in GDB. If an attacker could trick a user into loadingan executable containing malicious debugging information into GDB, they maybe able to execute arbitrary code with the privileges of the user.(CVE-2006-4146)SL 3.0.x SRPMS: gdb-6.3.0.0-1.138.el3.src.rpm i386: gdb-6.3.0.0-1.138.el3.i386.rpm gdb-6.3.0.0-1.138.el3.x86_64.rpm x86_64: gdb-6.3.0.0-1.138.el3.i386.rpm-Connie Sieh-Troy Dawson