SystemTap 1.1 Local Memory Corruption Vulnerabilities

Credit: Vincent Danen
Risk: High
Local: Yes
Remote: No
CWE: CWE-189

Ogólna skala CVSS: 4.9/10
Znaczenie: 6.9/10
Łatwość wykorzystania: 3.9/10
Wymagany dostęp: Lokalny
Złożoność ataku: Niska
Autoryzacja: Nie wymagana
Wpływ na poufność: Brak
Wpływ na integralność: Brak
Wpływ na dostępność: Pełny

Just a heads up that an issue in SystemTap was found where using the __get_argv() function in tapset could result in a crash of the SystemTap script that calls it (and syscall.execve) or, if it's running as root, could lead to a hang/crash of the system running the script. This flaw has been assigned CVE-2010-0411. More details can be found here: #!/bin/bash while [ "0" = "0" ] ; do HOME=1 /bin/echo /usr/src/kernels/2.6.18-128.el5-PAE-i686/include/*/* cat /proc/slabinfo done


Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2022,


Back to Top