SystemTap "staprun" Privilege Escalation Security Vulnerability
Release date:
Updated on:
Affected Systems:
SystemTap 1.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-2502
QEMU is an open source simulator software.
Qemu kvm has the Local Security Restriction Bypass Vulnerability in the implementation of the-runas parameter. Local attackers can exploit this vulnerability to bypass security restrictions and obtain illegal read/write permissions for some files.
The staprun program does not properly restrict the module search path. You can use the user space search and malicious module search paths to improve the permission.
<* Source: vendor
Link: http://secunia.com/advisories/45377/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SystemTap
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://sourceware.org/systemtap/