PT-2010-1047 · Red Hat · Systemtap-Runtime+9

Tavis Ormandy

·

Published

2010-11-17

·

Updated

2023-02-13

·

CVE-2010-4171

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions systemtap versions 1.1 through 1.2 systemtap-client versions 1.1 through 1.2 systemtap-initscript version 1.1 systemtap-server version 1.1 systemtap-sdt-devel version 1.1 systemtap-runtime version 1.1 systemtap-testsuite version 1.1 systemtap-debuginfo version 1.2
Description The issue affects the systemtap package and its components in Red Hat Enterprise Linux and CentOS operating systems. Multiple vulnerabilities in these packages can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out locally. According to Mitre, the staprun runtime tool in SystemTap does not verify that a module to unload was previously loaded by SystemTap, allowing local users to cause a denial of service by unloading arbitrary kernel modules.
Recommendations For systemtap versions 1.1 through 1.2, consider disabling the vulnerable components until a patch is available. For systemtap-client versions 1.1 through 1.2, restrict access to minimize the risk of exploitation. For systemtap-initscript version 1.1, systemtap-server version 1.1, systemtap-sdt-devel version 1.1, systemtap-runtime version 1.1, systemtap-testsuite version 1.1, and systemtap-debuginfo version 1.2, apply configuration changes to prevent local exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06053
BDU:2015-06054
BDU:2015-06056
BDU:2015-06057
BDU:2015-06059
BDU:2015-06062
BDU:2015-06064
BDU:2015-06066
BDU:2015-06068
BDU:2015-06070
BDU:2015-08645
BDU:2015-08646
BDU:2015-08647
BDU:2015-08648
BDU:2015-08649
BDU:2015-08650
BDU:2015-08651
BDU:2015-08652
BDU:2015-08653
BDU:2015-08654
CVE-2010-4171
DSA-2348-1
RHSA-2010:0894
RHSA-2010_0894

Affected Products

Centos
Red Hat
Systemtap
Systemtap-Client
Systemtap-Debuginfo
Systemtap-Initscript
Systemtap-Runtime
Systemtap-Sdt-Devel
Systemtap-Server
Systemtap-Testsuite