LWN.net Logo

systemtap: multiple DOS vulnerabilities

Package(s):systemtap CVE #(s):CVE-2009-2911
Created:October 27, 2009 Updated:October 28, 2009
Description: From the Fedora bug report:

Multiple denial of service flaws were found in the SystemTap instrumentation system, when the --unprivileged mode was activated:

a, Kernel stack overflow allows local attackers to cause denial of service or execute arbitrary code via long number of parameters, provided to the print* call.

b, Kernel stack frame overflow allows local attackers to cause denial of service via specially-crafted user-provided DWARF information.

c, Absent check(s) for the upper bound of the size of the unwind table and for the upper bound of the size of each of the CIE/CFI records, could allow an attacker to cause a denial of service (infinite loop).

Alerts:
Fedora FEDORA-2009-10719 2009-10-27
Fedora FEDORA-2009-10849 2009-10-27

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds