Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24022
HistoryApr 10, 2020 - 12:44 a.m.

Arbitrary Code Execution

2020-04-1000:44:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.099

Percentile

94.9%

systemtap is vulnerable to arbitrary code execution. The vulnerability exists as a flaw was found in the SystemTap compile server, stap-server, an optional component of SystemTap. This server did not adequately sanitize input provided by the stap-client program, which may allow a remote user to execute arbitrary shell code with the privileges of the compile server process, which could possibly be running as the root user.

References