Back to Database
Status published
Critical
CVE-2009-4273
stap-server in SystemTap before 1.1 allows remote attackers to execute...
Vulnerability Description
stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4273
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035201.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11417
- http://secunia.com/advisories/38154
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034036.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034041.html
- http://sourceware.org/systemtap/ftp/releases/systemtap-1.1.tar.gz
- http://secunia.com/advisories/39656
- https://bugzilla.redhat.com/show_bug.cgi?id=550172
- http://secunia.com/advisories/38216
- http://lists.fedoraproject.org/pipermail/scm-commits/2010-February/394714.html
- http://www.vupen.com/english/advisories/2010/0169
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html
- http://sourceware.org/ml/systemtap/2010-q1/msg00142.html
- http://sourceware.org/bugzilla/show_bug.cgi?id=11105
- http://www.redhat.com/support/errata/RHSA-2010-0124.html
- http://secunia.com/advisories/38765
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035261.html
- http://www.vupen.com/english/advisories/2010/1001
More from systemtap
View All →CVE-2012-0875
SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode...
Medium
5.4
CVE-2011-2503
The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool...
Low
3.7
CVE-2011-2502
runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before...
Medium
4.4
CVE-2011-1781
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows...
Low
1.2
CVE-2011-1769
SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is...
Low
1.2
Affected Vendor
systemtap
View all reports →Affected Software
systemtap
Vulnerable Versions:
0, 0.2.2, 0.3, 0.4, 0.5, 0.5.3, 0.5.4, 0.5.5, 0.5.7, 0.5.8, 0.5.9, 0.5.10, 0.5.12, 0.5.13, 0.5.14, 0.6, 0.6.2, 0.7, 0.7.2, 0.8, 0.9, 0.9.5, 0.9.7, 0.9.8, 0.9.9
Timeline
Official Publish:
January 26th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.