|
|
| |
|
| |
systemtap: denial of service
| Package(s): | systemtap |
CVE #(s): | CVE-2012-0875
|
| Created: | February 27, 2012 |
Updated: | March 18, 2013 |
| Description: |
From the Red Hat bugzilla:
A flaw was discovered in how systemtap handled DWARF expressions when
unwinding the stack. This could result in an invalid pointer read, leading to reading kernel memory, or a kernel panic (and if the kernel reboot on panic flag was set (panic_on_oops), it would cause the system to reboot).
In order to trigger this flaw, an admin would have to enable unprivileged mode (giving users membership in the 'stapusr' group and configuring the local machine with 'signer,all-users' stap-server trust). If an admin has enabled unprivileged mode, a user with such access could use this to crash the local machine. |
| Alerts: |
|
( Log in to post comments)
|
|
|