4.4

CVE-2011-2502

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

Data is provided by the National Vulnerability Database (NVD)
SystemtapSystemtap Version <= 1.5
SystemtapSystemtap Version0.2.2
SystemtapSystemtap Version0.3
SystemtapSystemtap Version0.4
SystemtapSystemtap Version0.5
SystemtapSystemtap Version0.5.3
SystemtapSystemtap Version0.5.4
SystemtapSystemtap Version0.5.5
SystemtapSystemtap Version0.5.7
SystemtapSystemtap Version0.5.8
SystemtapSystemtap Version0.5.9
SystemtapSystemtap Version0.5.10
SystemtapSystemtap Version0.5.12
SystemtapSystemtap Version0.5.13
SystemtapSystemtap Version0.5.14
SystemtapSystemtap Version0.6
SystemtapSystemtap Version0.6.2
SystemtapSystemtap Version0.7
SystemtapSystemtap Version0.7.2
SystemtapSystemtap Version0.8
SystemtapSystemtap Version0.9
SystemtapSystemtap Version0.9.5
SystemtapSystemtap Version0.9.7
SystemtapSystemtap Version0.9.8
SystemtapSystemtap Version0.9.9
SystemtapSystemtap Version1.0
SystemtapSystemtap Version1.1
SystemtapSystemtap Version1.2
SystemtapSystemtap Version1.3
SystemtapSystemtap Version1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.198
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.