3.7

CVE-2011-2503

The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SystemtapSystemtap Version <= 1.5
SystemtapSystemtap Version0.2.2
SystemtapSystemtap Version0.3
SystemtapSystemtap Version0.4
SystemtapSystemtap Version0.5
SystemtapSystemtap Version0.5.3
SystemtapSystemtap Version0.5.4
SystemtapSystemtap Version0.5.5
SystemtapSystemtap Version0.5.7
SystemtapSystemtap Version0.5.8
SystemtapSystemtap Version0.5.9
SystemtapSystemtap Version0.5.10
SystemtapSystemtap Version0.5.12
SystemtapSystemtap Version0.5.13
SystemtapSystemtap Version0.5.14
SystemtapSystemtap Version0.6
SystemtapSystemtap Version0.6.2
SystemtapSystemtap Version0.7
SystemtapSystemtap Version0.7.2
SystemtapSystemtap Version0.8
SystemtapSystemtap Version0.9
SystemtapSystemtap Version0.9.5
SystemtapSystemtap Version0.9.7
SystemtapSystemtap Version0.9.8
SystemtapSystemtap Version0.9.9
SystemtapSystemtap Version1.0
SystemtapSystemtap Version1.1
SystemtapSystemtap Version1.2
SystemtapSystemtap Version1.3
SystemtapSystemtap Version1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.303
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.7 1.9 6.4
AV:L/AC:H/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.