First published: Tue May 31 2011(Updated: )
SystemTap is an instrumentation system for systems running the Linux<br>kernel, version 2.6. Developers can write scripts to collect data on the<br>operation of the system.<br>A divide-by-zero flaw was found in the way SystemTap handled malformed<br>debugging information in DWARF format. When SystemTap unprivileged mode was<br>enabled, an unprivileged user in the stapusr group could use this flaw to<br>crash the system. Additionally, a privileged user (root, or a member of the<br>stapdev group) could trigger this flaw when tricked into instrumenting a<br>specially-crafted ELF binary, even when unprivileged mode was not enabled.<br>(CVE-2011-1769)<br>SystemTap users should upgrade to these updated packages, which contain a<br>backported patch to correct this issue.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/systemtap | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-client | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-initscript | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-runtime | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-sdt-devel | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-sdt-devel | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-server | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-testsuite | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-client | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-initscript | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-runtime | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-server | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
redhat/systemtap-testsuite | <1.3-4.el5_6.1 | 1.3-4.el5_6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.