SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs context variable access.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://secunia.com/advisories/44802 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=702687 | patch |
http://sourceware.org/git/?p=systemtap.git%3Ba=commit%3Bh=fa2e3415185a28542d419a641ecd6cddd52e3cd9 | |
http://www.securityfocus.com/bid/47934 | vdb entry |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:154 | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:155 | vendor advisory |
https://rhn.redhat.com/errata/RHSA-2011-0842.html | vendor advisory |
http://openwall.com/lists/oss-security/2011/05/20/2 | mailing list patch |