GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached. This can, for example, impede efforts to analyze malware with GDB.

Published : 2017-06-21 07:29 Updated : 2019-10-03 00:03

Score 4.3 / 10
Gnu Gdb 8.0
CWE-20 Improper Input Validation
CWE-770 Allocation of Resources Without Limits or Throttling

