Back

LOW

1.0: Multiple denial of service flaws once --unprivileged mode is activated

Published Oct 22, 2009

Description

SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 22, 2009
Updated Aug 7, 2024
Reserved Aug 20, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 21, 2009