|
|
| |
|
| |
systemtap: arbitrary code execution
| Package(s): | systemtap |
CVE #(s): | CVE-2009-4273
|
| Created: | January 18, 2010 |
Updated: | April 27, 2010 |
| Description: |
From the Red Hat bugzilla entry:
A flaw was found in the "stap-server" network compilation server, an optional
part of systemtap. Part of the server is written in bash and does not
adequately sanitize its inputs, which are essentially full command line
parameter sets from a client. Remote users may be able to abuse
quoting/spacing/metacharacters to execute shell code on behalf of the compile
server process/user (normally a fully unprivileged synthetic userid).
|
| Alerts: |
|
( Log in to post comments)
|
|
|