Oval Definition:oval:com.redhat.rhsa:def:20100125
Revision Date:2010-03-01Version:638
Title:RHSA-2010:0125: systemtap security update (Moderate)
Description:SystemTap is an instrumentation system for systems running the Linux kernel, version 2.6. Developers can write scripts to collect data on the operation of the system.

  • A buffer overflow flaw was found in SystemTap's tapset __get_argv() function. If a privileged user ran a SystemTap script that called this function, a local, unprivileged user could, while that script is still running, trigger this flaw and cause memory corruption by running a command with a large argument list, which may lead to a system crash or, potentially, arbitrary code execution with root privileges. (CVE-2010-0411)

    Note: SystemTap scripts that call __get_argv(), being a privileged function, can only be executed by the root user or users in the stapdev group. As well, if such a script was compiled and installed by root, users in the stapusr group would also be able to execute it.

    SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-0411
    RHSA-2010:0125
    RHSA-2010:0125-01
    RHSA-2010:0125-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • systemtap is earlier than 0:0.6.2-2.el4_8.1
  • AND systemtap is signed with Red Hat redhatrelease2 key
  • systemtap-runtime is earlier than 0:0.6.2-2.el4_8.1
  • AND systemtap-runtime is signed with Red Hat redhatrelease2 key
  • systemtap-testsuite is earlier than 0:0.6.2-2.el4_8.1
  • AND systemtap-testsuite is signed with Red Hat redhatrelease2 key
  • BACK