Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24666
HistoryApr 10, 2020 - 1:01 a.m.

Arbitrary Code Execution

2020-04-1001:01:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0

Percentile

5.1%

systemtap is vulnerable to arbitrary code execution. The vulnerability exists as it was found that SystemTap did not perform proper module path sanity checking if a user specified a custom path to the uprobes module, used when performing user-space probing (“staprun -u”). A local user who is a member of the stapusr group could use this flaw to bypass intended module-loading restrictions, allowing them to escalate their privileges by loading an arbitrary, unsigned module.