CVE-2011-2502
systemtap: insufficient security check when loading uprobes kernel module
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.
runtime/staprun/staprun_funcs.c en la herramienta de tiempo de ejecución systemtap (staprun) en SystemTap antes de v1.6 no valida correctamente los módulos cuando una ruta del módulo es especificada por un usuario para probar el espacio de usuario, lo que permite obtener privilegios a usuarios locales en el grupo stapusr a través de un módulo diseñado para tal fin en la ruta de búsqueda con el argumento -u.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-06-15 CVE Reserved
- 2011-07-26 CVE Published
- 2023-11-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/45377 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=716476 | 2011-07-25 | |
https://access.redhat.com/security/cve/CVE-2011-2502 | 2011-07-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | <= 1.5 Search vendor "Systemtap" for product "Systemtap" and version " <= 1.5" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.2.2 Search vendor "Systemtap" for product "Systemtap" and version "0.2.2" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.3 Search vendor "Systemtap" for product "Systemtap" and version "0.3" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.4 Search vendor "Systemtap" for product "Systemtap" and version "0.4" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5 Search vendor "Systemtap" for product "Systemtap" and version "0.5" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.3 Search vendor "Systemtap" for product "Systemtap" and version "0.5.3" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.4 Search vendor "Systemtap" for product "Systemtap" and version "0.5.4" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.5 Search vendor "Systemtap" for product "Systemtap" and version "0.5.5" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.7 Search vendor "Systemtap" for product "Systemtap" and version "0.5.7" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.8 Search vendor "Systemtap" for product "Systemtap" and version "0.5.8" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.9 Search vendor "Systemtap" for product "Systemtap" and version "0.5.9" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.10 Search vendor "Systemtap" for product "Systemtap" and version "0.5.10" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.12 Search vendor "Systemtap" for product "Systemtap" and version "0.5.12" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.13 Search vendor "Systemtap" for product "Systemtap" and version "0.5.13" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.5.14 Search vendor "Systemtap" for product "Systemtap" and version "0.5.14" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.6 Search vendor "Systemtap" for product "Systemtap" and version "0.6" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.6.2 Search vendor "Systemtap" for product "Systemtap" and version "0.6.2" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.7 Search vendor "Systemtap" for product "Systemtap" and version "0.7" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.7.2 Search vendor "Systemtap" for product "Systemtap" and version "0.7.2" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.8 Search vendor "Systemtap" for product "Systemtap" and version "0.8" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.9 Search vendor "Systemtap" for product "Systemtap" and version "0.9" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.9.5 Search vendor "Systemtap" for product "Systemtap" and version "0.9.5" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.9.7 Search vendor "Systemtap" for product "Systemtap" and version "0.9.7" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.9.8 Search vendor "Systemtap" for product "Systemtap" and version "0.9.8" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 0.9.9 Search vendor "Systemtap" for product "Systemtap" and version "0.9.9" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 1.0 Search vendor "Systemtap" for product "Systemtap" and version "1.0" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 1.1 Search vendor "Systemtap" for product "Systemtap" and version "1.1" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 1.2 Search vendor "Systemtap" for product "Systemtap" and version "1.2" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 1.3 Search vendor "Systemtap" for product "Systemtap" and version "1.3" | - |
Affected
| ||||||
Systemtap Search vendor "Systemtap" | Systemtap Search vendor "Systemtap" for product "Systemtap" | 1.4 Search vendor "Systemtap" for product "Systemtap" and version "1.4" | - |
Affected
|