PT-2010-1046 · Red Hat · Systemtap-Debuginfo+9

Tavis Ormandy

·

Published

2010-11-17

·

Updated

2023-02-13

·

CVE-2010-4170

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions systemtap versions 0.6.2 through 1.3 systemtap-runtime versions 0.6.2 through 1.1 systemtap-testsuite versions 0.6.2 through 1.1 systemtap-client versions 1.1 through 1.2 systemtap-server versions 1.1 systemtap-initscript versions 1.1 systemtap-debuginfo versions 1.2 systemtap-sdt-devel versions 1.1
Description The issue affects the systemtap package in Red Hat Enterprise Linux and CentOS operating systems. It allows local users to gain privileges by exploiting the vulnerability, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally. The staprun runtime tool in SystemTap does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE OPTIONS environment variable to specify a malicious configuration file.
Recommendations For systemtap versions 0.6.2 through 1.3, update to a version that contains a fix for this issue. For systemtap-runtime versions 0.6.2 through 1.1, update to a version that contains a fix for this issue. For systemtap-testsuite versions 0.6.2 through 1.1, update to a version that contains a fix for this issue. For systemtap-client versions 1.1 through 1.2, update to a version that contains a fix for this issue. For systemtap-server version 1.1, update to a version that contains a fix for this issue. For systemtap-initscript version 1.1, update to a version that contains a fix for this issue. For systemtap-debuginfo version 1.2, update to a version that contains a fix for this issue. For systemtap-sdt-devel version 1.1, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the staprun runtime tool until a patch is available. Avoid using the MODPROBE OPTIONS environment variable in the affected systemtap package until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-06053
BDU:2015-06054
BDU:2015-06056
BDU:2015-06057
BDU:2015-06059
BDU:2015-06062
BDU:2015-06064
BDU:2015-06066
BDU:2015-06068
BDU:2015-06070
BDU:2015-06946
BDU:2015-06949
BDU:2015-06952
BDU:2015-08642
BDU:2015-08643
BDU:2015-08644
BDU:2015-08645
BDU:2015-08646
BDU:2015-08647
BDU:2015-08648
BDU:2015-08649
BDU:2015-08650
BDU:2015-08651
BDU:2015-08652
BDU:2015-08653
BDU:2015-08654
CVE-2010-4170
DSA-2348-1
RHSA-2010:0894
RHSA-2010:0895
RHSA-2010_0894
RHSA-2010_0895

Affected Products

Centos
Red Hat
Systemtap
Systemtap-Client
Systemtap-Debuginfo
Systemtap-Initscript
Systemtap-Runtime
Systemtap-Sdt-Devel
Systemtap-Server
Systemtap-Testsuite