Lucene search

K
centosCentOS ProjectCESA-2011:1089
HistorySep 05, 2011 - 12:09 a.m.

systemtap security update

2011-09-0500:09:57
CentOS Project
lists.centos.org
41

CVSS2

3.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

CentOS Errata and Security Advisory CESA-2011:1089

SystemTap is an instrumentation system for systems running the Linux
kernel. The system allows developers to write scripts to collect data on
the operation of the system.

A race condition flaw was found in the way the staprun utility performed
module loading. A local user who is a member of the stapusr group could use
this flaw to modify a signed module while it is being loaded, allowing them
to escalate their privileges. (CVE-2011-2503)

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2011-September/080158.html
https://lists.centos.org/pipermail/centos-announce/2011-September/080160.html
https://lists.centos.org/pipermail/centos-cr-announce/2011-September/026560.html
https://lists.centos.org/pipermail/centos-cr-announce/2011-September/026561.html

Affected packages:
systemtap
systemtap-client
systemtap-initscript
systemtap-runtime
systemtap-sdt-devel
systemtap-server
systemtap-testsuite

Upstream details at:
https://access.redhat.com/errata/RHSA-2011:1089

CVSS2

3.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%