CVE-2005-1705: High severity GNU GDB vulnerability
Published May 24, 2005
·Updated
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
Affected Software
1 affected component
GNU GDB<=6.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 24, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1705?
CVE-2005-1705 is considered a high severity vulnerability.
2
How does CVE-2005-1705 affect users?
CVE-2005-1705 allows local users to execute arbitrary commands as the user running gdb.
3
How do I fix CVE-2005-1705?
To fix CVE-2005-1705, update gdb to version 6.3 or later.
4
What versions of gdb are impacted by CVE-2005-1705?
CVE-2005-1705 affects gdb versions prior to 6.3.
5
Is there a workaround for CVE-2005-1705?
A possible workaround for CVE-2005-1705 is to ensure that the .gdbinit file cannot be modified by untrusted users.