CVE-2011-2503: Input Validation
Published Jul 26, 2012
·Updated
The insertmodule function in runtime/staprun/staprunfuncs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.
Affected Software
30 affected components
SystemTap SystemTap<=1.5
SystemTap SystemTap=0.2.2
SystemTap SystemTap=0.3
SystemTap SystemTap=0.4
SystemTap SystemTap=0.5
SystemTap SystemTap=0.5.3
SystemTap SystemTap=0.5.4
SystemTap SystemTap=0.5.5
SystemTap SystemTap=0.5.7
SystemTap SystemTap=0.5.8
SystemTap SystemTap=0.5.9
SystemTap SystemTap=0.5.10
SystemTap SystemTap=0.5.12
SystemTap SystemTap=0.5.13
SystemTap SystemTap=0.5.14
SystemTap SystemTap=0.6
SystemTap SystemTap=0.6.2
SystemTap SystemTap=0.7
SystemTap SystemTap=0.7.2
SystemTap SystemTap=0.8
SystemTap SystemTap=0.9
SystemTap SystemTap=0.9.5
SystemTap SystemTap=0.9.7
SystemTap SystemTap=0.9.8
SystemTap SystemTap=0.9.9
SystemTap SystemTap=1.0
SystemTap SystemTap=1.1
SystemTap SystemTap=1.2
SystemTap SystemTap=1.3
SystemTap SystemTap=1.4
Remediation
Event History
Jul 26, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2503?
CVE-2011-2503 is considered a high severity vulnerability due to potential local privilege escalation.
2
How do I fix CVE-2011-2503?
To fix CVE-2011-2503, upgrade the SystemTap tool to version 1.6 or later.
3
Who is affected by CVE-2011-2503?
CVE-2011-2503 affects local users of SystemTap versions prior to 1.6.
4
What kind of vulnerability is CVE-2011-2503?
CVE-2011-2503 is a local privilege escalation vulnerability.
5
Can CVE-2011-2503 be exploited remotely?
No, CVE-2011-2503 can only be exploited locally by authenticated users.