Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 23 articles for you...
200

Scientific Linux SL5.x, SL6.x Moderate: SystemTap Security Update

Moderate: systemtap security update. Date: Wed, 21 Mar 2012 16:24:41 -0500 Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it. Sender: Security Errata for Scientific Linux From: Patrick Riehecky Subject: Security ERRATA Moderate: systemtap on SL5.x, SL6.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Moderate: systemtap security update Issue Date: 2012-03-08 CVE Numbers: CVE-2012-0875 SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. An invalid pointer read flaw was found in the way SystemTap handled malformed debugging information in DWARF format. When SystemTap unprivileged mode was enabled, an unprivileged user in the stapusr group could use this flaw to crash the system or, potentially, read arbitrary kernel memory. Additionally, a privileged user (root, or a member of the stapdev group) could trigger this flaw when tricked into instrumenting a specially-crafted ELF binary, even when unprivileged mode was not enabled. (CVE-2012-0875) SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue. SL5: i386 systemtap-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-initscript-1.6-7.el5_8.i386.rpm systemtap-runtime-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-server-1.6-7.el5_8.i386.rpm systemtap-testsuite-1.6-7.el5_8.i386.rpm x86_64 systemtap-1.6-7.el5_8.x86_64.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.x86_64.rpm systemtap-initscript-1.6-7.el5_8.x86_64.rpm systemtap-runtime-1.6-7.el5_8.x86_64.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.x86_64.rpm systemtap-server-1.6-7.el5_8.x86_64.rpm systemtap-testsuite-1.6-7.el5_8.x86_64.rpm SL6: i386 systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm x86_64 systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm - Scientific Linux Development Team . The recent security patch for SystemTap resolves a moderate vulnerability that impacts both Scientific Linux SL5.x and SL6.x distributions.. SystemTap Security Update, Scientific Linux Security, SystemTap Patch, Moderate Security Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 21, 2012 Important Scientific Linux
98

Red Hat Enterprise Linux 5 & 6: RHSA-2012-0376 Moderate: SystemTap Issue

Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: systemtap security update Advisory ID: RHSA-2012:0376-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:0376.html Issue date: 2012-03-08 CVE Names: CVE-2012-0875 ==================================================================== 1. Summary: Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. An invalid pointer read flaw was found in theway SystemTap handled malformed debugging information in DWARF format. When SystemTap unprivileged mode was enabled, an unprivileged user in the stapusr group could use this flaw to crash the system or, potentially, read arbitrary kernel memory. Additionally, a privileged user (root, or a member of the stapdev group) could trigger this flaw when tricked into instrumenting a specially-crafted ELF binary, even when unprivileged mode was not enabled. (CVE-2012-0875) SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 795913 - CVE-2012-0875 systemtap: kernel panic when processing malformed DWARF unwind data 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: systemtap-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-initscript-1.6-7.el5_8.i386.rpm systemtap-runtime-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-server-1.6-7.el5_8.i386.rpm systemtap-testsuite-1.6-7.el5_8.i386.rpm x86_64: systemtap-1.6-7.el5_8.x86_64.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.x86_64.rpm systemtap-initscript-1.6-7.el5_8.x86_64.rpm systemtap-runtime-1.6-7.el5_8.x86_64.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.x86_64.rpm systemtap-server-1.6-7.el5_8.x86_64.rpm systemtap-testsuite-1.6-7.el5_8.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: systemtap-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-initscript-1.6-7.el5_8.i386.rpm systemtap-runtime-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-server-1.6-7.el5_8.i386.rpm systemtap-testsuite-1.6-7.el5_8.i386.rpm ia64: systemtap-1.6-7.el5_8.ia64.rpm systemtap-debuginfo-1.6-7.el5_8.ia64.rpm systemtap-initscript-1.6-7.el5_8.ia64.rpm systemtap-runtime-1.6-7.el5_8.ia64.rpm systemtap-sdt-devel-1.6-7.el5_8.ia64.rpm systemtap-server-1.6-7.el5_8.ia64.rpm systemtap-testsuite-1.6-7.el5_8.ia64.rpm ppc: systemtap-1.6-7.el5_8.ppc64.rpm systemtap-debuginfo-1.6-7.el5_8.ppc64.rpm systemtap-initscript-1.6-7.el5_8.ppc64.rpm systemtap-runtime-1.6-7.el5_8.ppc64.rpm systemtap-sdt-devel-1.6-7.el5_8.ppc64.rpm systemtap-server-1.6-7.el5_8.ppc64.rpm systemtap-testsuite-1.6-7.el5_8.ppc64.rpm s390x: systemtap-1.6-7.el5_8.s390x.rpm systemtap-debuginfo-1.6-7.el5_8.s390.rpm systemtap-debuginfo-1.6-7.el5_8.s390x.rpm systemtap-initscript-1.6-7.el5_8.s390x.rpm systemtap-runtime-1.6-7.el5_8.s390x.rpm systemtap-sdt-devel-1.6-7.el5_8.s390.rpm systemtap-sdt-devel-1.6-7.el5_8.s390x.rpm systemtap-server-1.6-7.el5_8.s390x.rpm systemtap-testsuite-1.6-7.el5_8.s390x.rpm x86_64: systemtap-1.6-7.el5_8.x86_64.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.x86_64.rpm systemtap-initscript-1.6-7.el5_8.x86_64.rpm systemtap-runtime-1.6-7.el5_8.x86_64.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.x86_64.rpm systemtap-server-1.6-7.el5_8.x86_64.rpm systemtap-testsuite-1.6-7.el5_8.x86_64.rpm Red Hat Enterprise Linux Desktop (v.6): Source: i386: systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm x86_64: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm ppc64: systemtap-1.6-5.el6_2.ppc64.rpm systemtap-debuginfo-1.6-5.el6_2.ppc.rpm systemtap-debuginfo-1.6-5.el6_2.ppc64.rpm systemtap-grapher-1.6-5.el6_2.ppc64.rpm systemtap-initscript-1.6-5.el6_2.ppc64.rpm systemtap-runtime-1.6-5.el6_2.ppc64.rpm systemtap-sdt-devel-1.6-5.el6_2.ppc.rpm systemtap-sdt-devel-1.6-5.el6_2.ppc64.rpm systemtap-server-1.6-5.el6_2.ppc64.rpm s390x: systemtap-1.6-5.el6_2.s390x.rpm systemtap-debuginfo-1.6-5.el6_2.s390.rpm systemtap-debuginfo-1.6-5.el6_2.s390x.rpm systemtap-grapher-1.6-5.el6_2.s390x.rpm systemtap-initscript-1.6-5.el6_2.s390x.rpm systemtap-runtime-1.6-5.el6_2.s390x.rpm systemtap-sdt-devel-1.6-5.el6_2.s390.rpm systemtap-sdt-devel-1.6-5.el6_2.s390x.rpm systemtap-server-1.6-5.el6_2.s390x.rpm x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm ppc64: systemtap-debuginfo-1.6-5.el6_2.ppc64.rpm systemtap-testsuite-1.6-5.el6_2.ppc64.rpm s390x: systemtap-debuginfo-1.6-5.el6_2.s390x.rpm systemtap-testsuite-1.6-5.el6_2.s390x.rpm x86_64: systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm x86_64: systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2012-0875 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPWSGKXlSAg2UNWIIRAvFAAJwIXfxBUSPZQbu7tseyUmuzepisuQCdHQyF MPx37nmQkLrkKdztSb19fYA=VgOA -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . New systemtap packages resolve CVE-2012-0875 security issues for Red Hat with moderate impact, ensure system security.. SystemTap Update, Red Hat Security, Kernel Security Issue, Software Upgrade, Moderate Severity. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2012 Red Hat
98

Red Hat Enterprise Linux Advisory RHSA-2012:0376-01 SystemTap Crash Fix

Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: systemtap security update Advisory ID: RHSA-2012:0376-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:0376.html Issue date: 2012-03-08 CVE Names: CVE-2012-0875 ==================================================================== 1. Summary: Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. An invalid pointer read flaw was found in the way SystemTap handled malformed debugging information in DWARF format. When SystemTap unprivileged mode wasenabled, an unprivileged user in the stapusr group could use this flaw to crash the system or, potentially, read arbitrary kernel memory. Additionally, a privileged user (root, or a member of the stapdev group) could trigger this flaw when tricked into instrumenting a specially-crafted ELF binary, even when unprivileged mode was not enabled. (CVE-2012-0875) SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 795913 - CVE-2012-0875 systemtap: kernel panic when processing malformed DWARF unwind data 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: systemtap-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-initscript-1.6-7.el5_8.i386.rpm systemtap-runtime-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-server-1.6-7.el5_8.i386.rpm systemtap-testsuite-1.6-7.el5_8.i386.rpm x86_64: systemtap-1.6-7.el5_8.x86_64.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.x86_64.rpm systemtap-initscript-1.6-7.el5_8.x86_64.rpm systemtap-runtime-1.6-7.el5_8.x86_64.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.x86_64.rpm systemtap-server-1.6-7.el5_8.x86_64.rpm systemtap-testsuite-1.6-7.el5_8.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: systemtap-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-initscript-1.6-7.el5_8.i386.rpm systemtap-runtime-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-server-1.6-7.el5_8.i386.rpm systemtap-testsuite-1.6-7.el5_8.i386.rpm ia64: systemtap-1.6-7.el5_8.ia64.rpm systemtap-debuginfo-1.6-7.el5_8.ia64.rpm systemtap-initscript-1.6-7.el5_8.ia64.rpm systemtap-runtime-1.6-7.el5_8.ia64.rpm systemtap-sdt-devel-1.6-7.el5_8.ia64.rpm systemtap-server-1.6-7.el5_8.ia64.rpm systemtap-testsuite-1.6-7.el5_8.ia64.rpm ppc: systemtap-1.6-7.el5_8.ppc64.rpm systemtap-debuginfo-1.6-7.el5_8.ppc64.rpm systemtap-initscript-1.6-7.el5_8.ppc64.rpm systemtap-runtime-1.6-7.el5_8.ppc64.rpm systemtap-sdt-devel-1.6-7.el5_8.ppc64.rpm systemtap-server-1.6-7.el5_8.ppc64.rpm systemtap-testsuite-1.6-7.el5_8.ppc64.rpm s390x: systemtap-1.6-7.el5_8.s390x.rpm systemtap-debuginfo-1.6-7.el5_8.s390.rpm systemtap-debuginfo-1.6-7.el5_8.s390x.rpm systemtap-initscript-1.6-7.el5_8.s390x.rpm systemtap-runtime-1.6-7.el5_8.s390x.rpm systemtap-sdt-devel-1.6-7.el5_8.s390.rpm systemtap-sdt-devel-1.6-7.el5_8.s390x.rpm systemtap-server-1.6-7.el5_8.s390x.rpm systemtap-testsuite-1.6-7.el5_8.s390x.rpm x86_64: systemtap-1.6-7.el5_8.x86_64.rpm systemtap-debuginfo-1.6-7.el5_8.i386.rpm systemtap-debuginfo-1.6-7.el5_8.x86_64.rpm systemtap-initscript-1.6-7.el5_8.x86_64.rpm systemtap-runtime-1.6-7.el5_8.x86_64.rpm systemtap-sdt-devel-1.6-7.el5_8.i386.rpm systemtap-sdt-devel-1.6-7.el5_8.x86_64.rpm systemtap-server-1.6-7.el5_8.x86_64.rpm systemtap-testsuite-1.6-7.el5_8.x86_64.rpm Red Hat Enterprise Linux Desktop (v.6): Source: i386: systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm x86_64: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm ppc64: systemtap-1.6-5.el6_2.ppc64.rpm systemtap-debuginfo-1.6-5.el6_2.ppc.rpm systemtap-debuginfo-1.6-5.el6_2.ppc64.rpm systemtap-grapher-1.6-5.el6_2.ppc64.rpm systemtap-initscript-1.6-5.el6_2.ppc64.rpm systemtap-runtime-1.6-5.el6_2.ppc64.rpm systemtap-sdt-devel-1.6-5.el6_2.ppc.rpm systemtap-sdt-devel-1.6-5.el6_2.ppc64.rpm systemtap-server-1.6-5.el6_2.ppc64.rpm s390x: systemtap-1.6-5.el6_2.s390x.rpm systemtap-debuginfo-1.6-5.el6_2.s390.rpm systemtap-debuginfo-1.6-5.el6_2.s390x.rpm systemtap-grapher-1.6-5.el6_2.s390x.rpm systemtap-initscript-1.6-5.el6_2.s390x.rpm systemtap-runtime-1.6-5.el6_2.s390x.rpm systemtap-sdt-devel-1.6-5.el6_2.s390.rpm systemtap-sdt-devel-1.6-5.el6_2.s390x.rpm systemtap-server-1.6-5.el6_2.s390x.rpm x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm ppc64: systemtap-debuginfo-1.6-5.el6_2.ppc64.rpm systemtap-testsuite-1.6-5.el6_2.ppc64.rpm s390x: systemtap-debuginfo-1.6-5.el6_2.s390x.rpm systemtap-testsuite-1.6-5.el6_2.s390x.rpm x86_64: systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: systemtap-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-grapher-1.6-5.el6_2.i686.rpm systemtap-initscript-1.6-5.el6_2.i686.rpm systemtap-runtime-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-server-1.6-5.el6_2.i686.rpm x86_64: systemtap-1.6-5.el6_2.x86_64.rpm systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-grapher-1.6-5.el6_2.x86_64.rpm systemtap-initscript-1.6-5.el6_2.x86_64.rpm systemtap-runtime-1.6-5.el6_2.x86_64.rpm systemtap-sdt-devel-1.6-5.el6_2.i686.rpm systemtap-sdt-devel-1.6-5.el6_2.x86_64.rpm systemtap-server-1.6-5.el6_2.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: systemtap-debuginfo-1.6-5.el6_2.i686.rpm systemtap-testsuite-1.6-5.el6_2.i686.rpm x86_64: systemtap-debuginfo-1.6-5.el6_2.x86_64.rpm systemtap-testsuite-1.6-5.el6_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2012-0875 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. . Recent update for Red Hat RHEL 5 and 6 addresses moderate security concerns related to systemtap, including a fix for a critical kernel crash vulnerability.. systemtap update, security patch, Linux advisory. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2012 Red Hat
87

Debian: DSA-2348-1 Critical: SystemTap Privilege Escalation Issues

Several vulnerabilities were discovered in SystemTap, an instrumentation system for Linux: CVE-2011-2503 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2348-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff November 17, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : systemtap Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2010-4170 CVE-2010-4171 CVE-2011-2503 Several vulnerabilities were discovered in SystemTap, an instrumentation system for Linux: CVE-2011-2503 It was discovered that a race condition in staprun could lead to privilege escalation. CVE-2010-4170 It was discovered that insufficient validation of environment variables in staprun could lead to privilege escalation. CVE-2010-4171 It was discovered that insufficient validation of module unloading could lead to denial of service. For the stable distribution (squeeze), this problem has been fixed in version 1.2-5+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 1.6-1. We recommend that you upgrade your systemtap packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Update your SystemTap packages promptly after identifying significant security vulnerabilities that impact the reliability and safety of Debian.. SystemTap Security Update, Debian Advisory, Privilege Escalation Fix, Recent Security Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 20, 2011 Critical Debian
200

Scientific Linux: 2011-07-25 Moderate: SystemTap Privilege Escalation Risk

Moderate: systemtap security update. Date: Tue, 30 Aug 2011 11:46:31 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: systemtap on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." MIME-Version: 1.0 Synopsis: Moderate: systemtap security update Issue date: 2011-07-25 CVE Names: CVE-2011-2503 SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. A race condition flaw was found in the way the staprun utility performed module loading. A local user who is a member of the stapusr group could use this flaw to modify a signed module while it is being loaded, allowing them to escalate their privileges. (CVE-2011-2503) SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue SL 5.x SRPMS: systemtap-1.3-9.el5.src.rpm i386: systemtap-1.3-9.el5.i386.rpm systemtap-client-1.3-9.el5.i386.rpm systemtap-initscript-1.3-9.el5.i386.rpm systemtap-runtime-1.3-9.el5.i386.rpm systemtap-sdt-devel-1.3-9.el5.i386.rpm systemtap-server-1.3-9.el5.i386.rpm systemtap-testsuite-1.3-9.el5.i386.rpm x86_64: systemtap-1.3-9.el5.x86_64.rpm systemtap-client-1.3-9.el5.x86_64.rpm systemtap-initscript-1.3-9.el5.x86_64.rpm systemtap-runtime-1.3-9.el5.x86_64.rpm systemtap-sdt-devel-1.3-9.el5.i386.rpm systemtap-sdt-devel-1.3-9.el5.x86_64.rpm systemtap-server-1.3-9.el5.x86_64.rpm systemtap-testsuite-1.3-9.el5.x86_64.rpm - Scientific Linux Development Team lastline . Unveil a noteworthy security patch for SystemTap on Scientific Linux that rectifies a significant race condition vulnerability.. Security Advisory, SystemTap Update, Linux Kernel Threats, Scientific Linux Security. . LinuxSecurity.com Team

Calendar%202 Aug 30, 2011 Scientific Linux
200

Scientific Linux: 2011-07-25 Moderate: SystemTap Module Security Issues

Moderate: systemtap security update. Date: Thu, 28 Jul 2011 14:58:45 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: systemtap on SL6.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." MIME-Version: 1.0 Synopsis: Moderate: systemtap security update Issue Date: 2011-07-25 CVE Numbers: CVE-2011-2502 CVE-2011-2503 SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. It was found that SystemTap did not perform proper module path sanity checking if a user specified a custom path to the uprobes module, used when performing user-space probing ("staprun -u"). A local user who is a member of the stapusr group could use this flaw to bypass intended module-loading restrictions, allowing them to escalate their privileges by loading an arbitrary, unsigned module. (CVE-2011-2502) A race condition flaw was found in the way the staprun utility performed module loading. A local user who is a member of the stapusr group could use this flaw to modify a signed module while it is being loaded, allowing them to escalate their privileges. (CVE-2011-2503) SystemTap users should upgrade to these updated packages, which contain backported patches to correct these issues. SL6: i386 systemtap-1.4-6.el6_1.2.i686.rpm systemtap-testsuite-1.4-6.el6_1.2.i686.rpm systemtap-server-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-runtime-1.4-6.el6_1.2.i686.rpm systemtap-initscript-1.4-6.el6_1.2.i686.rpm systemtap-grapher-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-client-1.4-6.el6_1.2.i686.rpm x86_64 systemtap-server-1.4-6.el6_1.2.x86_64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.x86_64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-runtime-1.4-6.el6_1.2.x86_64.rpm systemtap-initscript-1.4-6.el6_1.2.x86_64.rpm systemtap-grapher-1.4-6.el6_1.2.x86_64.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-client-1.4-6.el6_1.2.x86_64.rpm systemtap-1.4-6.el6_1.2.x86_64.rpm systemtap-testsuite-1.4-6.el6_1.2.x86_64.rpm - Scientific Linux Development Team . Systemtap's incremental improvements bolster protection for Scientific Linux enthusiasts by addressing potential escalation of privileges threats.. systemtap security update, scientific linux advisory, privilege escalation, moderate severity update. . LinuxSecurity.com Team

Calendar%202 Jul 28, 2011 Scientific Linux
98

Red Hat: RHSA-2011:1089-01 Moderate: Systemtap Privilege Escalation

Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: systemtap security update Advisory ID: RHSA-2011:1089-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1089.html Issue date: 2011-07-25 CVE Names: CVE-2011-2503 ==================================================================== 1. Summary: Updated systemtap packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. A race condition flaw was found in the way the staprun utility performed module loading. A local user who is a member of the stapusr group could use this flaw to modify a signed module while it is being loaded, allowing them to escalate their privileges. (CVE-2011-2503) SystemTap users should upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red HatNetwork. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 716489 - CVE-2011-2503 systemtap: signed module loading race condition 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: systemtap-1.3-9.el5.i386.rpm systemtap-client-1.3-9.el5.i386.rpm systemtap-debuginfo-1.3-9.el5.i386.rpm systemtap-initscript-1.3-9.el5.i386.rpm systemtap-runtime-1.3-9.el5.i386.rpm systemtap-sdt-devel-1.3-9.el5.i386.rpm systemtap-server-1.3-9.el5.i386.rpm systemtap-testsuite-1.3-9.el5.i386.rpm x86_64: systemtap-1.3-9.el5.x86_64.rpm systemtap-client-1.3-9.el5.x86_64.rpm systemtap-debuginfo-1.3-9.el5.i386.rpm systemtap-debuginfo-1.3-9.el5.x86_64.rpm systemtap-initscript-1.3-9.el5.x86_64.rpm systemtap-runtime-1.3-9.el5.x86_64.rpm systemtap-sdt-devel-1.3-9.el5.i386.rpm systemtap-sdt-devel-1.3-9.el5.x86_64.rpm systemtap-server-1.3-9.el5.x86_64.rpm systemtap-testsuite-1.3-9.el5.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: systemtap-1.3-9.el5.i386.rpm systemtap-client-1.3-9.el5.i386.rpm systemtap-debuginfo-1.3-9.el5.i386.rpm systemtap-initscript-1.3-9.el5.i386.rpm systemtap-runtime-1.3-9.el5.i386.rpm systemtap-sdt-devel-1.3-9.el5.i386.rpm systemtap-server-1.3-9.el5.i386.rpm systemtap-testsuite-1.3-9.el5.i386.rpm ia64: systemtap-1.3-9.el5.ia64.rpm systemtap-client-1.3-9.el5.ia64.rpm systemtap-debuginfo-1.3-9.el5.ia64.rpm systemtap-initscript-1.3-9.el5.ia64.rpm systemtap-runtime-1.3-9.el5.ia64.rpm systemtap-sdt-devel-1.3-9.el5.ia64.rpm systemtap-server-1.3-9.el5.ia64.rpm systemtap-testsuite-1.3-9.el5.ia64.rpm ppc: systemtap-1.3-9.el5.ppc64.rpm systemtap-client-1.3-9.el5.ppc64.rpm systemtap-debuginfo-1.3-9.el5.ppc64.rpm systemtap-initscript-1.3-9.el5.ppc64.rpm systemtap-runtime-1.3-9.el5.ppc64.rpm systemtap-sdt-devel-1.3-9.el5.ppc64.rpm systemtap-server-1.3-9.el5.ppc64.rpm systemtap-testsuite-1.3-9.el5.ppc64.rpm s390x: systemtap-1.3-9.el5.s390x.rpm systemtap-client-1.3-9.el5.s390x.rpm systemtap-debuginfo-1.3-9.el5.s390.rpm systemtap-debuginfo-1.3-9.el5.s390x.rpm systemtap-initscript-1.3-9.el5.s390x.rpm systemtap-runtime-1.3-9.el5.s390x.rpm systemtap-sdt-devel-1.3-9.el5.s390.rpm systemtap-sdt-devel-1.3-9.el5.s390x.rpm systemtap-server-1.3-9.el5.s390x.rpm systemtap-testsuite-1.3-9.el5.s390x.rpm x86_64: systemtap-1.3-9.el5.x86_64.rpm systemtap-client-1.3-9.el5.x86_64.rpm systemtap-debuginfo-1.3-9.el5.i386.rpm systemtap-debuginfo-1.3-9.el5.x86_64.rpm systemtap-initscript-1.3-9.el5.x86_64.rpm systemtap-runtime-1.3-9.el5.x86_64.rpm systemtap-sdt-devel-1.3-9.el5.i386.rpm systemtap-sdt-devel-1.3-9.el5.x86_64.rpm systemtap-server-1.3-9.el5.x86_64.rpm systemtap-testsuite-1.3-9.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2011-2503 https://access.redhat.com/security/updates/classification#moderate 8.Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFOLfHUXlSAg2UNWIIRApeZAJwLnnuCjwpSJWXbD2UL+MykDnOPwQCgiSb3 HOf6huhiSMlDLTIZL5qRbL0=KfQT -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An upgraded systemtap package addresses a significant security vulnerability in Red Hat Enterprise Linux 5. Users are advised to perform the update promptly.. Systemtap Security, Red Hat Advisory, Linux Patch Management, Privilege Escalation Risk. . LinuxSecurity.com Team

Calendar%202 Jul 25, 2011 Red Hat
98

Red Hat Enterprise Linux 6: RHSA-2011-1088 Moderate: Security Issues

Updated systemtap packages that fix two security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: systemtap security update Advisory ID: RHSA-2011:1088-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1088.html Issue date: 2011-07-25 CVE Names: CVE-2011-2502 CVE-2011-2503 ==================================================================== 1. Summary: Updated systemtap packages that fix two security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: SystemTap is an instrumentation system for systems running the Linux kernel. The system allows developers to write scripts to collect data on the operation of the system. It was found that SystemTap did not perform proper module path sanity checking if a user specified a custom path to the uprobes module, used whenperforming user-space probing ("staprun -u"). A local user who is a member of the stapusr group could use this flaw to bypass intended module-loading restrictions, allowing them to escalate their privileges by loading an arbitrary, unsigned module. (CVE-2011-2502) A race condition flaw was found in the way the staprun utility performed module loading. A local user who is a member of the stapusr group could use this flaw to modify a signed module while it is being loaded, allowing them to escalate their privileges. (CVE-2011-2503) SystemTap users should upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 716476 - CVE-2011-2502 systemtap: insufficient security check when loading uprobes kernel module 716489 - CVE-2011-2503 systemtap: signed module loading race condition 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: systemtap-1.4-6.el6_1.2.i686.rpm systemtap-client-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-grapher-1.4-6.el6_1.2.i686.rpm systemtap-initscript-1.4-6.el6_1.2.i686.rpm systemtap-runtime-1.4-6.el6_1.2.i686.rpm x86_64: systemtap-1.4-6.el6_1.2.x86_64.rpm systemtap-client-1.4-6.el6_1.2.x86_64.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-grapher-1.4-6.el6_1.2.x86_64.rpm systemtap-initscript-1.4-6.el6_1.2.x86_64.rpm systemtap-runtime-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): Source: i386: systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-server-1.4-6.el6_1.2.i686.rpm systemtap-testsuite-1.4-6.el6_1.2.i686.rpm x86_64: systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.x86_64.rpm systemtap-server-1.4-6.el6_1.2.x86_64.rpm systemtap-testsuite-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: systemtap-1.4-6.el6_1.2.x86_64.rpm systemtap-client-1.4-6.el6_1.2.x86_64.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-initscript-1.4-6.el6_1.2.x86_64.rpm systemtap-runtime-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-grapher-1.4-6.el6_1.2.x86_64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.x86_64.rpm systemtap-server-1.4-6.el6_1.2.x86_64.rpm systemtap-testsuite-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: systemtap-1.4-6.el6_1.2.i686.rpm systemtap-client-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-grapher-1.4-6.el6_1.2.i686.rpm systemtap-initscript-1.4-6.el6_1.2.i686.rpm systemtap-runtime-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-server-1.4-6.el6_1.2.i686.rpm ppc64: systemtap-1.4-6.el6_1.2.ppc64.rpm systemtap-client-1.4-6.el6_1.2.ppc64.rpm systemtap-debuginfo-1.4-6.el6_1.2.ppc.rpm systemtap-debuginfo-1.4-6.el6_1.2.ppc64.rpm systemtap-grapher-1.4-6.el6_1.2.ppc64.rpm systemtap-initscript-1.4-6.el6_1.2.ppc64.rpm systemtap-runtime-1.4-6.el6_1.2.ppc64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.ppc.rpm systemtap-sdt-devel-1.4-6.el6_1.2.ppc64.rpm systemtap-server-1.4-6.el6_1.2.ppc64.rpm s390x: systemtap-1.4-6.el6_1.2.s390x.rpm systemtap-client-1.4-6.el6_1.2.s390x.rpm systemtap-debuginfo-1.4-6.el6_1.2.s390.rpm systemtap-debuginfo-1.4-6.el6_1.2.s390x.rpm systemtap-grapher-1.4-6.el6_1.2.s390x.rpm systemtap-initscript-1.4-6.el6_1.2.s390x.rpm systemtap-runtime-1.4-6.el6_1.2.s390x.rpm systemtap-sdt-devel-1.4-6.el6_1.2.s390.rpm systemtap-sdt-devel-1.4-6.el6_1.2.s390x.rpm systemtap-server-1.4-6.el6_1.2.s390x.rpm x86_64: systemtap-1.4-6.el6_1.2.x86_64.rpm systemtap-client-1.4-6.el6_1.2.x86_64.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-grapher-1.4-6.el6_1.2.x86_64.rpm systemtap-initscript-1.4-6.el6_1.2.x86_64.rpm systemtap-runtime-1.4-6.el6_1.2.x86_64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.x86_64.rpm systemtap-server-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): Source: i386: systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-testsuite-1.4-6.el6_1.2.i686.rpm ppc64: systemtap-debuginfo-1.4-6.el6_1.2.ppc64.rpm systemtap-testsuite-1.4-6.el6_1.2.ppc64.rpm s390x: systemtap-debuginfo-1.4-6.el6_1.2.s390x.rpm systemtap-testsuite-1.4-6.el6_1.2.s390x.rpm x86_64: systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-testsuite-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: systemtap-1.4-6.el6_1.2.i686.rpm systemtap-client-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-grapher-1.4-6.el6_1.2.i686.rpm systemtap-initscript-1.4-6.el6_1.2.i686.rpm systemtap-runtime-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-server-1.4-6.el6_1.2.i686.rpm x86_64: systemtap-1.4-6.el6_1.2.x86_64.rpm systemtap-client-1.4-6.el6_1.2.x86_64.rpm systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-grapher-1.4-6.el6_1.2.x86_64.rpm systemtap-initscript-1.4-6.el6_1.2.x86_64.rpm systemtap-runtime-1.4-6.el6_1.2.x86_64.rpm systemtap-sdt-devel-1.4-6.el6_1.2.i686.rpm systemtap-sdt-devel-1.4-6.el6_1.2.x86_64.rpm systemtap-server-1.4-6.el6_1.2.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: systemtap-debuginfo-1.4-6.el6_1.2.i686.rpm systemtap-testsuite-1.4-6.el6_1.2.i686.rpm x86_64: systemtap-debuginfo-1.4-6.el6_1.2.x86_64.rpm systemtap-testsuite-1.4-6.el6_1.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2011-2502 https://access.redhat.com/security/cve/CVE-2011-2503 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1.4.4 (GNU/Linux) iD8DBQFOLfG1XlSAg2UNWIIRAoc2AJ9/85u8O9Pj0XUjhmZtVudst/QLTACeLZIl w6H/suHSWRBfEhyx8vsOZRw=4I/f -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . SystemTap update released for RHEL 6 addresses critical security vulnerabilities impacting local user access. Patch recommended for immediate implementation.. SystemTap Security Update, Red Hat Enterprise Linux, Privilege Escalation. . LinuxSecurity.com Team

Calendar%202 Jul 25, 2011 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200