First published: Wed Mar 25 2009(Updated: )
Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Systemtap-sdt-devel | =0.0.20090314 | |
Red Hat Systemtap-sdt-devel | =0.0.20080705 | |
Debian Linux | =5.0 | |
Debian Linux | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0784 is considered a critical vulnerability due to its ability to allow local users to gain elevated privileges.
To fix CVE-2009-0784, update SystemTap to a version later than 0.0.20090314 or 0.0.20080705.
CVE-2009-0784 affects local users in the stapusr group on systems running vulnerable versions of SystemTap.
Attackers can exploit CVE-2009-0784 to insert arbitrary SystemTap kernel modules and gain elevated privileges.
Versions 0.0.20080705 and 0.0.20090314 of SystemTap are identified as vulnerable in CVE-2009-0784.