CVE Vulnerabilities

CVE-2010-4170

Published: Dec 07, 2010 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH

The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.

Affected Software

Name Vendor Start Version End Version
Systemtap Systemtap 1.3 (including) 1.3 (including)
Red Hat Enterprise Linux 4 RedHat systemtap-0:0.6.2-2.el4_8.3 *
Red Hat Enterprise Linux 5 RedHat systemtap-0:1.1-3.el5_5.3 *
Red Hat Enterprise Linux 6 RedHat systemtap-0:1.2-11.el6_0 *
Systemtap Ubuntu devel *
Systemtap Ubuntu maverick *

References