The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Systemtap | Systemtap | 1.3 (including) | 1.3 (including) |
| Red Hat Enterprise Linux 4 | RedHat | systemtap-0:0.6.2-2.el4_8.3 | * |
| Red Hat Enterprise Linux 5 | RedHat | systemtap-0:1.1-3.el5_5.3 | * |
| Red Hat Enterprise Linux 6 | RedHat | systemtap-0:1.2-11.el6_0 | * |
| Systemtap | Ubuntu | devel | * |
| Systemtap | Ubuntu | maverick | * |