LWN.net Logo

systemtap: denial of service

Package(s):systemtap CVE #(s):CVE-2011-1781 CVE-2011-1769
Created:May 27, 2011 Updated:October 17, 2011
Description: From the Fedora advisory:

Two divide-by-zero flaws were found in the way systemtap interpreted certain corrupted DWARF expressions. A privileged user able to execute arbitrary systemtap scripts could be tricked into triggering this flaw to crash the target machine. An unprivileged user (in the stapusr group) may be able to trigger this flaw to crash the target machine, only if unprivileged mode was enabled by the system administrator.

Alerts:
Mandriva MDVSA-2011:155 2011-10-17
Mandriva MDVSA-2011:154 2011-10-17
Scientific Linux SL-syst-20110531 2011-05-31
CentOS CESA-2011:0841 2011-05-31
Red Hat RHSA-2011:0842-01 2011-05-31
Red Hat RHSA-2011:0841-01 2011-05-31
Fedora FEDORA-2011-7289 2011-05-20
Fedora FEDORA-2011-7302 2011-05-20
Fedora FEDORA-2011-7314 2011-05-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds