Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SystemTap 权限许可和访问控制问题漏洞
Vulnerability Description
SystemTap是一个开源的Linux系统调试和跟踪工具,可以用于实时监视和诊断运行中的Linux系统的各种活动。 SystemTap 1.3版本存在权限许可和访问控制问题漏洞,该漏洞源于没有正确清理环境,使得本地用户可以通过设置MODPROBE_OPTIONS环境变量指定恶意配置文件来获取权限。
CVSS Information
N/A
Vulnerability Type
N/A