Oval Definition:oval:com.redhat.rhsa:def:20110842
Revision Date:2011-05-31Version:639
Title:RHSA-2011:0842: systemtap security update (Moderate)
Description:SystemTap is an instrumentation system for systems running the Linux kernel, version 2.6. Developers can write scripts to collect data on the operation of the system.

  • Two divide-by-zero flaws were found in the way SystemTap handled malformed debugging information in DWARF format. When SystemTap unprivileged mode was enabled, an unprivileged user in the stapusr group could use these flaws to crash the system. Additionally, a privileged user (root, or a member of the stapdev group) could trigger these flaws when tricked into instrumenting a specially-crafted ELF binary, even when unprivileged mode was not enabled. (CVE-2011-1769, CVE-2011-1781)

    SystemTap users should upgrade to these updated packages, which contain a backported patch to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-1769
    CVE-2011-1769
    CVE-2011-1781
    CVE-2011-1781
    RHSA-2011:0842
    RHSA-2011:0842-01
    RHSA-2011:0842-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • systemtap is earlier than 0:1.4-6.el6_1.1
  • AND systemtap is signed with Red Hat redhatrelease2 key
  • systemtap-client is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-client is signed with Red Hat redhatrelease2 key
  • systemtap-grapher is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-grapher is signed with Red Hat redhatrelease2 key
  • systemtap-initscript is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-initscript is signed with Red Hat redhatrelease2 key
  • systemtap-runtime is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-runtime is signed with Red Hat redhatrelease2 key
  • systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-sdt-devel is signed with Red Hat redhatrelease2 key
  • systemtap-server is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-server is signed with Red Hat redhatrelease2 key
  • systemtap-testsuite is earlier than 0:1.4-6.el6_1.1
  • AND systemtap-testsuite is signed with Red Hat redhatrelease2 key
  • BACK