LWN.net Logo

systemtap: denial of service

Package(s):systemtap CVE #(s):CVE-2010-0411 CVE-2010-0412
Created:February 19, 2010 Updated:April 27, 2010
Description: From the CVE entries:

Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.

Alerts:
SuSE SUSE-SR:2010:010 2010-04-27
Fedora FEDORA-2010-1720 2010-02-18
Fedora FEDORA-2010-1373 2010-02-18
CentOS CESA-2010:0124 2010-03-02
CentOS CESA-2010:0125 2010-03-01
Red Hat RHSA-2010:0125-01 2010-03-01
Red Hat RHSA-2010:0124-01 2010-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds