CVE-2012-0875
SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data,…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.
- CVSS 2.0
- 5.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:N/A:C
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- systemtap/systemtap
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00057.html
- http://permalink.gmane.org/gmane.comp.security.oss.general/6987
- http://rhn.redhat.com/errata/RHSA-2012-0376.html
- http://securitytracker.com/id?1026777
- http://sourceware.org/bugzilla/show_bug.cgi?id=13714
- http://sourceware.org/git/?p=systemtap.git%3Ba=commit%3Bh=64b0cff3b
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00057.html
- http://permalink.gmane.org/gmane.comp.security.oss.general/6987
- http://rhn.redhat.com/errata/RHSA-2012-0376.html
- http://securitytracker.com/id?1026777
- http://sourceware.org/bugzilla/show_bug.cgi?id=13714
- http://sourceware.org/git/?p=systemtap.git%3Ba=commit%3Bh=64b0cff3b
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.