Record summary

CVE-2010-0411 has a selected CVSS score of 4.9; EIP currently links 1 catalogued exploit.

Description

Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSystemTap 1.0/1.1 - '__get_argv()' / '__get_compat_argv()' Local Memory CorruptionExploitDB exploitby Josh StoneNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 20