SciLinux: CVE-2006-4146 SL4 gdb i386/x86_64
Summary
Date: Wed, 9 May 2007 15:13:54 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for SL4 gdb i386/x86_64Comments: To: scientific Synopsis: Low: gdb security and bug fix updateIssue date: 2007-05-01CVE Names: CVE-2006-4146Various buffer overflows and underflows were found in the DWARF expressioncomputation stack in GDB. If a user loaded an executable containingmalicious debugging information into GDB, an attacker might be able toexecute arbitrary code with the privileges of the user. (CVE-2006-4146)SRPMS: gdb-6.3.0.0-1.143.el4.src.rpmi386: gdb-6.3.0.0-1.143.el4.i386.rpmx86_64: gdb-6.3.0.0-1.143.el4.x86_64.rpm-Connie Sieh-Troy Dawson