PT-2011-1095 · Red Hat · Systemtap+1

Published

2011-07-25

·

Updated

2012-07-27

·

CVE-2011-2502

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SystemTap versions 1.4 SystemTap before version 1.6
Description The issue concerns multiple vulnerabilities in the SystemTap package of Red Hat Enterprise Linux, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. Specifically, the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, allowing local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.
Recommendations For SystemTap versions 1.4, update to a version later than 1.4 to resolve the issue. For SystemTap before version 1.6, update to version 1.6 or later to address the vulnerability in the systemtap runtime tool (staprun). As a temporary workaround, consider restricting access to the stapusr group to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06055
BDU:2015-06058
BDU:2015-06060
BDU:2015-06061
BDU:2015-06063
BDU:2015-06065
BDU:2015-06067
BDU:2015-06069
BDU:2015-06071
CVE-2011-2502
RHSA-2011:1088
RHSA-2011_1088

Affected Products

Red Hat
Systemtap