Lucene search

K
nvd[email protected]NVD:CVE-2011-2502
HistoryJul 26, 2012 - 7:55 p.m.

CVE-2011-2502

2012-07-2619:55:00
CWE-20
web.nvd.nist.gov
3

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

Affected configurations

Nvd
Node
systemtapsystemtapRange1.5
OR
systemtapsystemtapMatch0.2.2
OR
systemtapsystemtapMatch0.3
OR
systemtapsystemtapMatch0.4
OR
systemtapsystemtapMatch0.5
OR
systemtapsystemtapMatch0.5.3
OR
systemtapsystemtapMatch0.5.4
OR
systemtapsystemtapMatch0.5.5
OR
systemtapsystemtapMatch0.5.7
OR
systemtapsystemtapMatch0.5.8
OR
systemtapsystemtapMatch0.5.9
OR
systemtapsystemtapMatch0.5.10
OR
systemtapsystemtapMatch0.5.12
OR
systemtapsystemtapMatch0.5.13
OR
systemtapsystemtapMatch0.5.14
OR
systemtapsystemtapMatch0.6
OR
systemtapsystemtapMatch0.6.2
OR
systemtapsystemtapMatch0.7
OR
systemtapsystemtapMatch0.7.2
OR
systemtapsystemtapMatch0.8
OR
systemtapsystemtapMatch0.9
OR
systemtapsystemtapMatch0.9.5
OR
systemtapsystemtapMatch0.9.7
OR
systemtapsystemtapMatch0.9.8
OR
systemtapsystemtapMatch0.9.9
OR
systemtapsystemtapMatch1.0
OR
systemtapsystemtapMatch1.1
OR
systemtapsystemtapMatch1.2
OR
systemtapsystemtapMatch1.3
OR
systemtapsystemtapMatch1.4
VendorProductVersionCPE
systemtapsystemtap*cpe:2.3:a:systemtap:systemtap:*:*:*:*:*:*:*:*
systemtapsystemtap0.2.2cpe:2.3:a:systemtap:systemtap:0.2.2:*:*:*:*:*:*:*
systemtapsystemtap0.3cpe:2.3:a:systemtap:systemtap:0.3:*:*:*:*:*:*:*
systemtapsystemtap0.4cpe:2.3:a:systemtap:systemtap:0.4:*:*:*:*:*:*:*
systemtapsystemtap0.5cpe:2.3:a:systemtap:systemtap:0.5:*:*:*:*:*:*:*
systemtapsystemtap0.5.3cpe:2.3:a:systemtap:systemtap:0.5.3:*:*:*:*:*:*:*
systemtapsystemtap0.5.4cpe:2.3:a:systemtap:systemtap:0.5.4:*:*:*:*:*:*:*
systemtapsystemtap0.5.5cpe:2.3:a:systemtap:systemtap:0.5.5:*:*:*:*:*:*:*
systemtapsystemtap0.5.7cpe:2.3:a:systemtap:systemtap:0.5.7:*:*:*:*:*:*:*
systemtapsystemtap0.5.8cpe:2.3:a:systemtap:systemtap:0.5.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%