Release date: 2011-11-28
Updated on: 2011-11-29
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50829
Cve id: CVE-2011-4355
Linux is the kernel of a free computer.
The GNU Debugger (gdb) tool in Linux has a vulnerability. After the. debug_gdb_scripts is defined, gdb loads suspicious files from the current directory, causing arbitrary code execution with the current user permission.
<* Source: Doug Evans
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 703238
Http://permalink.gmane.org/gmane.comp.security.oss.general/6367
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.kernel.org/