Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69716
Category:Fedora Local Security Checks
Title:Fedora Core 15 FEDORA-2011-7314 (systemtap)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to systemtap
announced via advisory FEDORA-2011-7314.

Update Information:

Two divide-by-zero flaws were found in the way systemtap interpreted certain corrupted
DWARF expressions. A privileged user able to execute arbitrary systemtap scripts could be
tricked into triggering this flaw to crash the target machine. An unprivileged user (in the
stapusr group) may be able to trigger this flaw to crash the target machine, only if unprivileged
mode was enabled by the system administrator.

References:

[ 1 ] Bug #703972 - CVE-2011-1781 systemtap: divide by zero stack unwinding flaw
https://bugzilla.redhat.com/show_bug.cgi?id=703972
[ 2 ] Bug #702687 - CVE-2011-1769 systemtap: does not guard against DWARF operations div-by-zero errors, which can cause a kernel panic
https://bugzilla.redhat.com/show_bug.cgi?id=702687

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update systemtap' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-7314

Risk factor : Low

CVSS Score:
1.2

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1781
44802
http://secunia.com/advisories/44802
47934
http://www.securityfocus.com/bid/47934
MDVSA-2011:155
http://www.mandriva.com/security/advisories?name=MDVSA-2011:155
RHSA-2011:0842
https://rhn.redhat.com/errata/RHSA-2011-0842.html
[oss-security] 20110520 systemtap divide-by-zero issues (CVE-2011-1769, CVE-2011-1781)
http://openwall.com/lists/oss-security/2011/05/20/2
http://sourceware.org/git/?p=systemtap.git%3Ba=commit%3Bh=fa2e3415185a28542d419a641ecd6cddd52e3cd9
https://bugzilla.redhat.com/show_bug.cgi?id=702687
Common Vulnerability Exposure (CVE) ID: CVE-2011-1769
MDVSA-2011:154
http://www.mandriva.com/security/advisories?name=MDVSA-2011:154
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.