LWN.net Logo

systemtap: arbitrary code execution

Package(s):systemtap CVE #(s):CVE-2009-4273
Created:January 18, 2010 Updated:April 27, 2010
Description:

From the Red Hat bugzilla entry:

A flaw was found in the "stap-server" network compilation server, an optional part of systemtap. Part of the server is written in bash and does not adequately sanitize its inputs, which are essentially full command line parameter sets from a client. Remote users may be able to abuse quoting/spacing/metacharacters to execute shell code on behalf of the compile server process/user (normally a fully unprivileged synthetic userid).

Alerts:
SuSE SUSE-SR:2010:010 2010-04-27
Fedora FEDORA-2010-1720 2010-02-18
Fedora FEDORA-2010-0688 2010-01-17
Fedora FEDORA-2010-0671 2010-01-17
CentOS CESA-2010:0124 2010-03-02
Red Hat RHSA-2010:0124-01 2010-03-01
Fedora FEDORA-2010-1373 2010-02-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds