CVE-2010-0411

Systemtap - Numeric Error

Title source: rule

Description

Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Josh Stone · bashlocallinux
https://www.exploit-db.com/exploits/33604

Scores

EPSS 0.0013
EPSS Percentile 31.5%

Details

CWE
CWE-189
Status published
Products (1)
systemtap/systemtap 1.1
Published Feb 08, 2010
Tracked Since Feb 18, 2026