Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmjv-9hc6-6rf5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

EPSS

Процентиль: 24%
0.00076
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 13 лет назад

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

redhat
почти 14 лет назад

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

nvd
почти 13 лет назад

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

debian
почти 13 лет назад

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun ...

oracle-oval
почти 14 лет назад

ELSA-2011-1088: systemtap security update (MODERATE)

EPSS

Процентиль: 24%
0.00076
Низкий

Дефекты

CWE-20