Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24023
HistoryApr 10, 2020 - 12:44 a.m.

Denial Of Service (DoS)

2020-04-1000:44:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.001

Percentile

26.5%

systemtap is vulnerable to denial of service (DoS). The vulnerability exists as a buffer overflow flaw was found in SystemTap’s tapset __get_argv() function. If a privileged user ran a SystemTap script that called this function, a local, unprivileged user could, while that script is still running, trigger this flaw and cause memory corruption by running a command with a large argument list, which may lead to a system crash or, potentially, arbitrary code execution with root privileges.

References