National Cyber Awareness System
Vulnerability Summary for CVE-2010-0411
Original release date:02/08/2010
Last revised:08/21/2010
Source:
US-CERT/NIST
Overview
Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
6.9
Exploitability Subscore:
3.9
CVSS Version 2 Metrics:
Access Vector: Locally exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Allows disruption of serviceUnknown
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
External Source: CONFIRM
Name: https://bugzilla.redhat.com/show_bug.cgi?id=559719
External Source: VUPEN
Name: ADV-2010-1001
External Source: BID
Name: 38120
External Source: REDHAT
Name: RHSA-2010:0125
External Source: REDHAT
Name: RHSA-2010:0124
External Source: CONFIRM
Name: http://sourceware.org/git/gitweb.cgi?p=systemtap.git;a=commit;h=a2d399c87a642190f08ede63dc6fc434a5a8363a
External Source: CONFIRM
Name: http://sourceware.org/bugzilla/show_bug.cgi?id=11234
External Source: SECTRACK
Name: 1023664
External Source: SECUNIA
Name: 39656
External Source: SECUNIA
Name: 38817
External Source: SECUNIA
Name: 38765
External Source: SECUNIA
Name: 38680
External Source: SECUNIA
Name: 38426
Type: Advisory
External Source: OVAL
Name: oval:org.mitre.oval:def:9675
External Source: MLIST
Name: [oss-security] 20100204 systemtap DoS issue (CVE-2010-0411)
External Source: SUSE
Name: SUSE-SR:2010:010
External Source: FEDORA
Name: FEDORA-2010-1720
External Source: FEDORA
Name: FEDORA-2010-1373
References to Check Content
Identifier:oval:org.mitre.oval:def:9675
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5