4.3
CVSSv2

CVE-2017-9778

Published: 21/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

GNU Debugger (GDB) 8.0 and previous versions fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached. This can, for example, impede efforts to analyze malware with GDB.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gdb

Vendor Advisories

Debian Bug report logs - #865607 gdb: CVE-2017-9778: Fail to detect invalid FDE header, can exhaust gdb process's virtual memory and terminate debug session Package: src:gdb; Maintainer for src:gdb is Héctor Orón Martínez <zumbi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Jun 20 ...
GNU Debugger (GDB) 80 and earlier fails to detect a negative length field in a DWARF section A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached This can, for example, impede efforts to analyze malware with GDB ...