CVE-2023-39130: Buffer Overflow
Published Jul 25, 2023
·Updated
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function peas16() at /gdb/coff-pe-read.c.
Affected Software
7 affected componentsFixes available
GNU GDB=13.0.50.20220805-git
Microsoft azl3 crash 8.0.4-3
Microsoft azl3 gdb 13.2-4
Microsoft azl3 gdb 13.2-3
Microsoft cbl2 crash 8.0.1-3
Microsoft azl3 crash 8.0.4-4
Microsoft cbl2 gdb 11.2-3
Event History
Jul 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
07:15 PM
Description
Nov 1, 2024
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39130?
CVE-2023-39130 is a vulnerability in GNU gdb (GDB) 13.0.50.20220805-git that allows a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.
2
How severe is CVE-2023-39130?
CVE-2023-39130 has a severity rating of medium with a score of 5.5.
3
How can I fix CVE-2023-39130?
To fix CVE-2023-39130, update GNU gdb (GDB) to version 13.0.50.20220805-git or later.
4
Is there any reference for CVE-2023-39130?
Yes, you can find more information about CVE-2023-39130 at https://sourceware.org/bugzilla/show_bug.cgi?id=30641.
5
What are the Common Weakness Enumerations (CWEs) associated with CVE-2023-39130?
The Common Weakness Enumerations (CWEs) associated with CVE-2023-39130 are CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).