First published: Tue May 31 2011(Updated: )
SystemTap is an instrumentation system for systems running the Linux<br>kernel, version 2.6. Developers can write scripts to collect data on the<br>operation of the system.<br>Two divide-by-zero flaws were found in the way SystemTap handled malformed<br>debugging information in DWARF format. When SystemTap unprivileged mode was<br>enabled, an unprivileged user in the stapusr group could use these flaws to<br>crash the system. Additionally, a privileged user (root, or a member of the<br>stapdev group) could trigger these flaws when tricked into instrumenting a<br>specially-crafted ELF binary, even when unprivileged mode was not enabled.<br>(CVE-2011-1769, CVE-2011-1781)<br>SystemTap users should upgrade to these updated packages, which contain a<br>backported patch to correct these issues.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/systemtap | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-client | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-debuginfo | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-debuginfo | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-grapher | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-initscript | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-runtime | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-sdt-devel | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-sdt-devel | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-server | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-testsuite | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-client | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-grapher | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-initscript | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-runtime | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-server | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
redhat/systemtap-testsuite | <1.4-6.el6_1.1 | 1.4-6.el6_1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.