CVE-2009-0784: Race Condition
Published Mar 25, 2009
·Updated
Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.
Affected Software
4 affected components
SystemTap SystemTap=0.0.20090314
SystemTap SystemTap=0.0.20080705
Debian Debian Linux=5.0
Debian Debian Linux=4.0
Remediation
Patch Available
Event History
Mar 25, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0784?
CVE-2009-0784 is considered a critical vulnerability due to its ability to allow local users to gain elevated privileges.
2
How do I fix CVE-2009-0784?
To fix CVE-2009-0784, update SystemTap to a version later than 0.0.20090314 or 0.0.20080705.
3
Who is affected by CVE-2009-0784?
CVE-2009-0784 affects local users in the stapusr group on systems running vulnerable versions of SystemTap.
4
What can attackers do with CVE-2009-0784?
Attackers can exploit CVE-2009-0784 to insert arbitrary SystemTap kernel modules and gain elevated privileges.
5
What versions of SystemTap are vulnerable to CVE-2009-0784?
Versions 0.0.20080705 and 0.0.20090314 of SystemTap are identified as vulnerable in CVE-2009-0784.