PT-2010-1072 · Systemtap+1 · Systemtap-Client+7

Vincent Danen

·

Published

2010-01-26

·

Updated

2024-06-15

·

CVE-2009-4273

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions systemtap-testsuite versions 0.9.7 systemtap-server versions 0.9.7 systemtap-client versions 0.9.7 systemtap-initscript versions 0.9.7 systemtap-runtime versions 0.9.7 systemtap versions 0.9.7 systemtap-sdt-devel versions 0.9.7
Description The issue involves multiple vulnerabilities in the systemtap package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. According to Mitre, the stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a request.
Recommendations For systemtap-testsuite version 0.9.7, update to a version that contains a fix for this issue. For systemtap-server version 0.9.7, update to a version that contains a fix for this issue. For systemtap-client version 0.9.7, update to a version that contains a fix for this issue. For systemtap-initscript version 0.9.7, update to a version that contains a fix for this issue. For systemtap-runtime version 0.9.7, update to a version that contains a fix for this issue. For systemtap version 0.9.7, update to a version that contains a fix for this issue. For systemtap-sdt-devel version 0.9.7, update to a version that contains a fix for this issue. As a temporary workaround, consider disabling the stap-server until a patch is available. Restrict access to the systemtap package to minimize the risk of exploitation. Avoid using the stap command-line arguments in the affected systemtap package until the issue is resolved.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06540
BDU:2015-06541
BDU:2015-06542
BDU:2015-06543
BDU:2015-06544
BDU:2015-06545
BDU:2015-06546
BDU:2015-08574
BDU:2015-08575
BDU:2015-08576
BDU:2015-08577
BDU:2015-08578
BDU:2015-08579
BDU:2015-08580
CVE-2009-4273
OPENSUSE-SU-2024:10506-1
RHSA-2010:0124
RHSA-2010_0124

Affected Products

Red Hat
Systemtap
Systemtap-Client
Systemtap-Initscript
Systemtap-Runtime
Systemtap-Sdt-Devel
Systemtap-Server
Systemtap-Testsuite