CVE Vulnerabilities

CVE-2010-4170

Published: Dec 07, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.

Affected Software

NameVendorStart VersionEnd Version
SystemtapSystemtap1.3 (including)1.3 (including)
Red Hat Enterprise Linux 4RedHatsystemtap-0:0.6.2-2.el4_8.3*
Red Hat Enterprise Linux 5RedHatsystemtap-0:1.1-3.el5_5.3*
Red Hat Enterprise Linux 6RedHatsystemtap-0:1.2-11.el6_0*
SystemtapUbuntudevel*
SystemtapUbuntumaverick*

References