Oval Definition:oval:com.redhat.rhsa:def:20111088
Revision Date:2011-07-25Version:640
Title:RHSA-2011:1088: systemtap security update (Moderate)
Description:SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system.

  • It was found that SystemTap did not perform proper module path sanity checking if a user specified a custom path to the uprobes module, used when performing user-space probing ("staprun -u"). A local user who is a member of the stapusr group could use this flaw to bypass intended module-loading restrictions, allowing them to escalate their privileges by loading an arbitrary, unsigned module. (CVE-2011-2502)

  • A race condition flaw was found in the way the staprun utility performed module loading. A local user who is a member of the stapusr group could use this flaw to modify a signed module while it is being loaded, allowing them to escalate their privileges. (CVE-2011-2503)

    SystemTap users should upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-2502
    CVE-2011-2502
    CVE-2011-2503
    CVE-2011-2503
    RHSA-2011:1088
    RHSA-2011:1088-01
    RHSA-2011:1088-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • systemtap is earlier than 0:1.4-6.el6_1.2
  • AND systemtap is signed with Red Hat redhatrelease2 key
  • systemtap-client is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-client is signed with Red Hat redhatrelease2 key
  • systemtap-grapher is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-grapher is signed with Red Hat redhatrelease2 key
  • systemtap-initscript is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-initscript is signed with Red Hat redhatrelease2 key
  • systemtap-runtime is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-runtime is signed with Red Hat redhatrelease2 key
  • systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-sdt-devel is signed with Red Hat redhatrelease2 key
  • systemtap-server is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-server is signed with Red Hat redhatrelease2 key
  • systemtap-testsuite is earlier than 0:1.4-6.el6_1.2
  • AND systemtap-testsuite is signed with Red Hat redhatrelease2 key
  • BACK