CVE-2010-4170

Publication date 7 December 2010

Last updated 24 July 2024


Ubuntu priority

Description

The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.

Status

Package Ubuntu Release Status
systemtap 10.10 maverick
Fixed 1.3-1ubuntu0.1
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities