VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-4170
systemtap: The staprun runtime tool in SystemTap 1.3 does not ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4170

Original

The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-12-07
Source Information Category:
Advisory, Alert
Last Updated:
2010-12-08




Affected Product Tags
cpe:/a:systemtap:systemtap:1.3
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
BID 44914




CONFIRM http://sources.redhat.com/git/gitweb.cgi?p=systemtap.git;a=commit;h=b7565b41228bea196cefa3a7d43ab67f8f9152e2




EXPLOIT-DB 15620




FEDORA FEDORA-2010-17873




FEDORA FEDORA-2010-17868




FEDORA FEDORA-2010-17865




MLIST [systemtap] 20101117 important systemtap security fix




REDHAT RHSA-2010:0895




REDHAT RHSA-2010:0894




SECTRACK 1024754




SECUNIA 42318




SECUNIA 42306




SECUNIA 42263




SECUNIA 42256




Vulnerability Type Permissions, Privileges, and Access Control (CWE-264)




XF systemtap-staprun-priv-escalation(63344)





Copyright © 2010 JPCERT/CC All Rights Reserved.