Vulnerability CVE-2010-0411


Published: 2010-02-08   Modified: 2012-02-13

Description:
Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.

See advisories in our WLB2 database:
Topic
Author
Date
High
SystemTap 1.1 Local Memory Corruption Vulnerabilities
Vincent Danen
11.02.2010

Type:

CWE-189

(Numeric Errors)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Systemtap -> Systemtap 

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=559719
http://www.vupen.com/english/advisories/2010/1001
http://www.securityfocus.com/bid/38120
http://www.redhat.com/support/errata/RHSA-2010-0125.html
http://www.redhat.com/support/errata/RHSA-2010-0124.html
http://sourceware.org/git/gitweb.cgi?p=systemtap.git;a=commit;h=a2d399c87a642190f08ede63dc6fc434a5a8363a
http://sourceware.org/bugzilla/show_bug.cgi?id=11234
http://securitytracker.com/id?1023664
http://secunia.com/advisories/39656
http://secunia.com/advisories/38817
http://secunia.com/advisories/38765
http://secunia.com/advisories/38680
http://secunia.com/advisories/38426
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9675
http://marc.info/?l=oss-security&m=126530657715364&w=2
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035261.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035201.html

Copyright 2024, cxsecurity.com

 

Back to Top