CVE-2023-39129: Use After Free
Published Jul 25, 2023
·Updated
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function addpeexportedsym() at /gdb/coff-pe-read.c.
Affected Software
7 affected componentsFixes available
GNU GDB=13.0.50.20220805-git
Microsoft azl3 gdb 13.2-4
Microsoft azl3 gdb 13.2-3
Microsoft azl3 crash 8.0.4-3
Microsoft azl3 crash 8.0.4-4
Microsoft cbl2 gdb 11.2-3
Microsoft cbl2 crash 8.0.1-3
Event History
Jul 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
07:15 PM
Description
Nov 1, 2024
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this heap use after free vulnerability?
The vulnerability ID is CVE-2023-39129.
2
What is the severity rating of CVE-2023-39129?
The severity rating is medium (5.5).
3
What software version is affected by CVE-2023-39129?
GNU gdb (GDB) 13.0.50.20220805-git is affected by this vulnerability.
4
How can this heap use after free vulnerability be exploited?
This vulnerability can be exploited by an attacker to execute arbitrary code or cause a denial-of-service (DoS) condition.
5
Is there a patch available to fix CVE-2023-39129?
A patch has not yet been released for this vulnerability. It is recommended to update to a fixed version when it becomes available.