[Secure-testing-team] Bug#603946: CVE-2010-4170 and CVE-2010-4171

Moritz Muehlenhoff jmm at debian.org
Thu Nov 18 18:39:00 UTC 2010


Package: systemtap
Severity: grave
Tags: security

Two security issues have been found in systemtap, one of them
allowing local privilege escalation:

http://sources.redhat.com/ml/systemtap/2010-q4/msg00230.html

These are CVE-2010-4170 and CVE-2010-4171.

Fix:
http://sources.redhat.com/git/gitweb.cgi?p=systemtap.git;a=commit;h=b7565b41228bea196cefa3a7d43ab67f8f9152e2


Cheers,
        Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages systemtap depends on:
ii  libc6                         2.11.2-6   Embedded GNU C Library: Shared lib
ii  libelf1                       0.148-1    library to read and write ELF file
ii  libgcc1                       1:4.4.5-3  GCC support library
ii  libsqlite3-0                  3.7.2-1    SQLite 3 shared library
ii  libstdc++6                    4.4.5-3    The GNU Standard C++ Library v3
pn  systemtap-runtime             <none>     (no description available)

systemtap recommends no packages.

Versions of packages systemtap suggests:
pn  systemtap-doc                 <none>     (no description available)
pn  vim-addon-manager             <none>     (no description available)





More information about the Secure-testing-team mailing list