SystemTap 1.0, when the --unprivileged option is used, does not...
Vulnerability Description
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2911
Credits & Attribution
No credits recorded in the NVD database.
References
- http://sources.redhat.com/bugzilla/show_bug.cgi?id=10750
- https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00793.html
- http://gcc.gnu.org/bugzilla/show_bug.cgi?id=41633
- http://www.openwall.com/lists/oss-security/2009/10/21/1
- https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00627.html
- https://bugzilla.redhat.com/show_bug.cgi?id=529175
- http://secunia.com/advisories/37167
- http://www.securityfocus.com/bid/36778
- http://www.vupen.com/english/advisories/2009/2989
More from systemtap
View All →Affected Vendor
systemtap
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.