LOW
Systemtap: Ability to remove unused modules by unprivileged user
Published Dec 7, 2010
2.1
LOWCVSS 2.0
EPSS 0.40%
Description
The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
systemtap-0:1.1-3.el5_5.3
Fixed · RHSA-2010:0894
Red Hat Enterprise Linux 6
systemtap-0:1.2-11.el6_0
Fixed · RHSA-2010:0894
Red Hat Enterprise Linux 4
systemtap
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | systemtap-0:1.1-3.el5_5.3 | Fixed | RHSA-2010:0894 |
| Red Hat Enterprise Linux 6 | systemtap-0:1.2-11.el6_0 | Fixed | RHSA-2010:0894 |
| Red Hat Enterprise Linux 4 | systemtap | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of the systemtap package as shipped with Red Hat Enterprise Linux 4.
Weaknesses (1)
References (18)
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051115.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051122.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051127.html vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/42256 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42263 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42318 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/46920 third-party-advisoryx_refsource_SECUNIA
- http://sources.redhat.com/git/gitweb.cgi?p=systemtap.git%3Ba=commit%3Bh=b7565b41228bea196cefa3a7d43ab67f8f9152e2 x_refsource_CONFIRM
- http://sources.redhat.com/ml/systemtap/2010-q4/msg00230.html mailing-listx_refsource_MLIST
- http://www.debian.org/security/2011/dsa-2348 vendor-advisoryx_refsource_DEBIAN
- http://www.redhat.com/support/errata/RHSA-2010-0894.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/44917 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1024754 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2010-4171 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=653606 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/63345 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-4171
- https://www.cve.org/CVERecord?id=CVE-2010-4171
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 7, 2010
Updated Aug 7, 2024
Reserved Nov 4, 2010
Link CVE-2010-4171
CISA Vulnrichment
Updated n/a