Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in systemtap
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in systemtap
ID: FEDORA-2011-7289
Distribution: Fedora
Plattformen: Fedora 13
Datum: Fr, 27. Mai 2011, 05:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1781
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1769
Applikationen: Systemtap

Originalnachricht

Name        : systemtap
Product : Fedora 13
Version : 1.4
Release : 6.fc13
URL : http://sourceware.org/systemtap/
Summary : Instrumentation System
Description :
SystemTap is an instrumentation system for systems running Linux 2.6.
Developers can write instrumentation to collect data on the operation
of the system.

-------------------------------------------------------------------------------
-
Update Information:

Two divide-by-zero flaws were found in the way systemtap interpreted certain
corrupted
DWARF expressions. A privileged user able to execute arbitrary systemtap
scripts could be
tricked into triggering this flaw to crash the target machine. An unprivileged
user (in the
stapusr group) may be able to trigger this flaw to crash the target machine,
only if unprivileged
mode was enabled by the system administrator.
-------------------------------------------------------------------------------
-
ChangeLog:

* Wed May 18 2011 Frank Ch. Eigler <fche@redhat.com> - 1.4-6
- CVE-2011-1781, CVE-2011-1769
* Sun Feb 13 2011 Dennis Gilmore <dennis@ausil.us> - 1.4-5
- no crash on sparc
* Wed Feb 9 2011 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org> - 1.4-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Wed Jan 19 2011 Frank Ch. Eigler <fche@redhat.com> - 1.4-3
- adapt to kernel CLONE_STOPPED deprecation
- adapt to gcc 4.6 unused variable warnings
* Wed Jan 19 2011 Stan Cox <scox@redhat.com> - 1.4-2
- sdt fixes
* Mon Jan 17 2011 Frank Ch. Eigler <fche@redhat.com> - 1.4-1
- Upstream release.
* Tue Dec 7 2010 Dan Horák <dan[at]danny.cz> - 1.3-4
- publican now needs a versioned BR (see /usr/bin/publican for details)
* Tue Nov 16 2010 David Smith <dsmith@redhat.com> - 1.3-3
- CVE-2010-4170
- CVE-2010-4171
* Wed Jul 21 2010 Josh Stone <jistone@redhat.com> - 1.3-2
- Disable crash on ppc.
* Wed Jul 21 2010 Josh Stone <jistone@redhat.com> - 1.3-1
- Upstream release.
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #703972 - CVE-2011-1781 systemtap: divide by zero stack unwinding
flaw
https://bugzilla.redhat.com/show_bug.cgi?id=703972
[ 2 ] Bug #702687 - CVE-2011-1769 systemtap: does not guard against DWARF
operations div-by-zero errors, which can cause a kernel panic
https://bugzilla.redhat.com/show_bug.cgi?id=702687
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update systemtap' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung