SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
BID:38120
Info
SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
| Bugtraq ID: | 38120 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0411 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 05 2010 12:00AM |
| Updated: | Apr 27 2010 04:52PM |
| Credit: | Josh Stone |
| Vulnerable: |
SystemTap SystemTap 1.1 SystemTap SystemTap 1.0 S.u.S.E. openSUSE 11.2 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop version 4 Red Hat Fedora 12 Red Hat Fedora 11 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 SP1 |
| Not Vulnerable: | |
Discussion
SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
SystemTap is prone to multiple local memory-corruption vulnerabilities.
An attacker may exploit these issues to execute arbitrary code with SYSTEM privileges. Failed exploit attempts will result in a denial of service.
SystemTap 1.1 is vulnerable; other versions may also be affected.
SystemTap is prone to multiple local memory-corruption vulnerabilities.
An attacker may exploit these issues to execute arbitrary code with SYSTEM privileges. Failed exploit attempts will result in a denial of service.
SystemTap 1.1 is vulnerable; other versions may also be affected.
Exploit / POC
SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
References:
References:
- [PATCH] PR11234: Rewrite __get_argv without embedded-C (Josh Stone)
- Avaya Security Advisory ASA-2010-061 (Avaya)
- Bug 11234 - __get_argv can overflow its return buffer (Josh Stone)
- Bug 559719 �?? CVE-2010-0411 systemtap: Crash with systemtap script using __get_ar (Red Hat Bugzilla)
- SystemTap Homepage (SystemTap)