CVE-2011-1781
systemtap: divide by zero stack unwinding flaw
Severity Score
1.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs stack unwinding (aka backtracing).
SystemTap 1.4, (también conocido como stapusr) cuando el modo no privilegiado está habilitado, permite a usuarios locales provocar una denegación de servicio (error de división por cero y OOPS) a través de un programa de ELF modificado con expresiones DWARF que no están bien mipulado por una secuencia de comandos STAP que realiza acondicionamiento de la pila (también conocido como rastreo).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2011-04-19 CVE Reserved
- 2011-06-01 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://openwall.com/lists/oss-security/2011/05/20/2 | Mailing List | |
http://secunia.com/advisories/44802 | Third Party Advisory | |
http://sourceware.org/git/?p=systemtap.git%3Ba=commit%3Bh=fa2e3415185a28542d419a641ecd6cddd52e3cd9 | X_refsource_confirm | |
http://www.securityfocus.com/bid/47934 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=702687 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2011:155 | 2023-02-13 | |
https://rhn.redhat.com/errata/RHSA-2011-0842.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2011-1781 | 2011-05-31 | |
https://bugzilla.redhat.com/show_bug.cgi?id=703972 | 2011-05-31 |