PT-2009-1062 · Red Hat · Systemtap+1

Erik Sjoelund

·

Published

2009-03-25

·

Updated

2020-11-04

·

CVE-2009-0784

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SystemTap stap tool versions 0.0.20080705 through 0.0.20090314 systemtap-client version 0.7.2 systemtap-testsuite version 0.7.2 systemtap-runtime version 0.7.2 systemtap-server version 0.7.2 systemtap version 0.7.2
Description The issue is related to a race condition in the SystemTap stap tool, which allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerability can be carried out locally.
Recommendations For SystemTap stap tool versions 0.0.20080705 through 0.0.20090314, consider disabling the stap tool until a patch is available. For systemtap-client version 0.7.2, restrict access to the client to minimize the risk of exploitation. For systemtap-testsuite version 0.7.2, avoid using the testsuite until the issue is resolved. For systemtap-runtime version 0.7.2, consider disabling the runtime environment until a patch is available. For systemtap-server version 0.7.2, restrict access to the server to minimize the risk of exploitation. For systemtap version 0.7.2, consider disabling the systemtap functionality until a patch is available.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06947
BDU:2015-06948
BDU:2015-06950
BDU:2015-06951
BDU:2015-06953
BDU:2015-08494
BDU:2015-08495
BDU:2015-08496
BDU:2015-08497
BDU:2015-08498
CVE-2009-0784
DSA-1755-1
RHSA-2009:0373
RHSA-2009_0373

Affected Products

Red Hat
Systemtap