CVE-2023-39128

CVSS 3.1 Score 5.5 of 10 (medium)

Attack Complexity low
Availability high
Confidentiality none
Integrity none
Scope unchanged
Privileges Required none

Details

Published Jul 25, 2023
Updated: Aug 3, 2023
CWE ID 787

Summary

CVE-2023-39128 is a vulnerability found in GNU gdb (GDB) 13.0.50.20220805-git, specifically in the function ada_decode at /gdb/ada-lang.c, which results in a stack overflow. The vulnerability has a base severity rating of MEDIUM with a base score of 5.5. It requires user interaction and can be exploited locally, without any privileges required. Although it does not have any impact on integrity or confidentiality, it has a high availability impact. The vulnerability has an exploitability score of 1.8 and an impact score of 3.6 out of 10. It falls under the category of CWE-787 (Out-of-bounds Write). No remediation steps or potential danger to organizations are mentioned in the provided information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share