Lucene search

K
cve[email protected]CVE-2009-0784
HistoryMar 25, 2009 - 11:30 p.m.

CVE-2009-0784

2009-03-2523:30:00
CWE-362
web.nvd.nist.gov
28
cve-2009-0784
systemtap
race condition
stap tool
kernel modules
privilege escalation

CVSS2

6.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.

Affected configurations

NVD
Node
systemtapsystemtapMatch0.0.20080705
OR
systemtapsystemtapMatch0.0.20090314
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
VendorProductVersionCPE
systemtapsystemtap0.0.20080705cpe:/a:systemtap:systemtap:0.0.20080705:::
systemtapsystemtap0.0.20090314cpe:/a:systemtap:systemtap:0.0.20090314:::

CVSS2

6.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%