Abusing GDB features for data ingress and egress
archcloudlabs.com
archcloudlabs.com
I agree that compromising a distro server is unlikely, but I suppose a mitm attack could be plausible though, and this would give arbitrary code execution.
EDIT: or is it ACE? The article seems to emphasize sending arbitrary _data_ to the client, so now I'm confused. If you can make the binary print something else, surely you have ACE? Or do you have to step through the code?
which is how Debian generates the -debug packages [1].
[1] https://github.com/Debian/debhelper/blob/master/dh_strip