vendor:
GNU gdbserver
by:
Roberto Gesteira Miñarro (7Rocky)
8.8
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: GNU gdbserver
Affected Version From: 9.2
Affected Version To: 9.2
Patch Exists: YES
Related CWE:
CPE: a:gnu:gdb:9.2
Platforms Tested: Ubuntu Linux (gdbserver debugging x64 and x86 binaries)
2021
GNU gdbserver 9.2 – Remote Command Execution (RCE)
GNU gdbserver is vulnerable to a Remote Command Execution (RCE) vulnerability. An attacker can send a specially crafted packet to the gdbserver, which will execute arbitrary code on the target system. The vulnerability is due to the lack of proper validation of user-supplied input when handling the 'vCont' command. This allows an attacker to send a malicious payload to the gdbserver, which will be executed on the target system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of GNU gdbserver.