Oval Definition:oval:com.redhat.rhsa:def:20120376
Revision Date:2012-03-08Version:634
Title:RHSA-2012:0376: systemtap security update (Moderate)
Description:SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system.

  • An invalid pointer read flaw was found in the way SystemTap handled malformed debugging information in DWARF format. When SystemTap unprivileged mode was enabled, an unprivileged user in the stapusr group could use this flaw to crash the system or, potentially, read arbitrary kernel memory. Additionally, a privileged user (root, or a member of the stapdev group) could trigger this flaw when tricked into instrumenting a specially-crafted ELF binary, even when unprivileged mode was not enabled. (CVE-2012-0875)

    SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-0875
    CVE-2012-0875
    RHSA-2012:0376
    RHSA-2012:0376-01
    RHSA-2012:0376-01
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • systemtap is earlier than 0:1.6-5.el6_2
  • AND systemtap is signed with Red Hat redhatrelease2 key
  • systemtap-grapher is earlier than 0:1.6-5.el6_2
  • AND systemtap-grapher is signed with Red Hat redhatrelease2 key
  • systemtap-initscript is earlier than 0:1.6-5.el6_2
  • AND systemtap-initscript is signed with Red Hat redhatrelease2 key
  • systemtap-runtime is earlier than 0:1.6-5.el6_2
  • AND systemtap-runtime is signed with Red Hat redhatrelease2 key
  • systemtap-sdt-devel is earlier than 0:1.6-5.el6_2
  • AND systemtap-sdt-devel is signed with Red Hat redhatrelease2 key
  • systemtap-server is earlier than 0:1.6-5.el6_2
  • AND systemtap-server is signed with Red Hat redhatrelease2 key
  • systemtap-testsuite is earlier than 0:1.6-5.el6_2
  • AND systemtap-testsuite is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • systemtap is earlier than 0:1.6-7.el5_8
  • AND systemtap is signed with Red Hat redhatrelease2 key
  • systemtap-initscript is earlier than 0:1.6-7.el5_8
  • AND systemtap-initscript is signed with Red Hat redhatrelease2 key
  • systemtap-runtime is earlier than 0:1.6-7.el5_8
  • AND systemtap-runtime is signed with Red Hat redhatrelease2 key
  • systemtap-sdt-devel is earlier than 0:1.6-7.el5_8
  • AND systemtap-sdt-devel is signed with Red Hat redhatrelease2 key
  • systemtap-server is earlier than 0:1.6-7.el5_8
  • AND systemtap-server is signed with Red Hat redhatrelease2 key
  • systemtap-testsuite is earlier than 0:1.6-7.el5_8
  • AND systemtap-testsuite is signed with Red Hat redhatrelease2 key
  • BACK