PT-2009-5261 · Systemtap · Systemtap
Jan Lieskovsky
·
Publicado
2009-10-22
·
Atualizado
2024-06-15
·
CVE-2009-2911
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
SystemTap version 1.0
Description:
The issue allows local users to cause a denial of service or gain privileges via certain operations that trigger kernel stack overflows. This can be achieved through print operations with a large number of arguments or crafted DWARF expressions. Additionally, it can cause a denial of service via infinite loops triggered by the creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.
Recommendations:
For SystemTap version 1.0, avoid using the --unprivileged option until a patch is available. As a temporary workaround, consider restricting the number of arguments in print operations and limiting the complexity of DWARF expressions to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Systemtap