← Back

CVE-2011-2502

nvd nist
Published: Jul 26, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

Affected (30)

Products: Systemtap: Systemtap
1 product
Systemtap
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Systemtap
Up to 1.5
Version 0.2.2
Version 0.3
Version 0.4
Version 0.5.10
Version 0.5.12
Version 0.5.13
Version 0.5.14
Version 0.5.3
Version 0.5.4
Version 0.5.5
Version 0.5.7
Version 0.5.8
Version 0.5.9
Version 0.5
Version 0.6.2
Version 0.6
Version 0.7.2
Version 0.7
Version 0.8
Version 0.9.5
Version 0.9.7
Version 0.9.8
Version 0.9.9
Version 0.9
Version 1.0
Version 1.1
Version 1.2
Version 1.3
Version 1.4

Timeline

No history available yet.