CVE

Id
50415  
CVE No.
CVE-2011-2503  
Status
Candidate  
Description
The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.  
Phase
Assigned (20110615)  
Votes
None (candidate not yet proposed)  
Comments