3.7

CVE-2011-2503

The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.

Data is provided by the National Vulnerability Database (NVD)
SystemtapSystemtap Version <= 1.5
SystemtapSystemtap Version0.2.2
SystemtapSystemtap Version0.3
SystemtapSystemtap Version0.4
SystemtapSystemtap Version0.5
SystemtapSystemtap Version0.5.3
SystemtapSystemtap Version0.5.4
SystemtapSystemtap Version0.5.5
SystemtapSystemtap Version0.5.7
SystemtapSystemtap Version0.5.8
SystemtapSystemtap Version0.5.9
SystemtapSystemtap Version0.5.10
SystemtapSystemtap Version0.5.12
SystemtapSystemtap Version0.5.13
SystemtapSystemtap Version0.5.14
SystemtapSystemtap Version0.6
SystemtapSystemtap Version0.6.2
SystemtapSystemtap Version0.7
SystemtapSystemtap Version0.7.2
SystemtapSystemtap Version0.8
SystemtapSystemtap Version0.9
SystemtapSystemtap Version0.9.5
SystemtapSystemtap Version0.9.7
SystemtapSystemtap Version0.9.8
SystemtapSystemtap Version0.9.9
SystemtapSystemtap Version1.0
SystemtapSystemtap Version1.1
SystemtapSystemtap Version1.2
SystemtapSystemtap Version1.3
SystemtapSystemtap Version1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.303
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.7 1.9 6.4
AV:L/AC:H/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.