CVE-2010-4170: High severity SystemTap SystemTap vulnerability
Published Dec 7, 2010
·Updated
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBEOPTIONS environment variable to specify a malicious configuration file.
Affected Software
1 affected component
SystemTap SystemTap=1.3
Event History
Dec 7, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4170?
CVE-2010-4170 is classified with medium severity due to potential local privilege escalation.
2
How do I fix CVE-2010-4170?
To fix CVE-2010-4170, upgrade SystemTap to a version newer than 1.3 that addresses this vulnerability.
3
Who is affected by CVE-2010-4170?
Local users running SystemTap version 1.3 are affected by CVE-2010-4170.
4
What type of vulnerability is CVE-2010-4170?
CVE-2010-4170 is a local privilege escalation vulnerability.
5
What can an attacker do with CVE-2010-4170?
An attacker can gain elevated privileges by manipulating the MODPROBE_OPTIONS environment variable.