[SECURITY] Fedora 15 Update: systemtap-1.4-9.fc15

updates at fedoraproject.org updates at fedoraproject.org
Thu May 26 21:53:51 UTC 2011


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-7314
2011-05-20 20:33:50
--------------------------------------------------------------------------------

Name        : systemtap
Product     : Fedora 15
Version     : 1.4
Release     : 9.fc15
URL         : http://sourceware.org/systemtap/
Summary     : Instrumentation System
Description :
SystemTap is an instrumentation system for systems running Linux 2.6.
Developers can write instrumentation to collect data on the operation
of the system.

--------------------------------------------------------------------------------
Update Information:

Two divide-by-zero flaws were found in the way systemtap interpreted certain corrupted
DWARF expressions.  A privileged user able to execute arbitrary systemtap scripts could be
tricked into triggering this flaw to crash the target machine.  An unprivileged user (in the
stapusr group) may be able to trigger this flaw to crash the target machine, only if unprivileged
mode was enabled by the system administrator.
--------------------------------------------------------------------------------
ChangeLog:

* Wed May 18 2011 Frank Ch. Eigler <fche at redhat.com> - 1.4-9
- Disable documentation builds temporarily, due to bug #704298.
* Wed May 18 2011 Frank Ch. Eigler <fche at redhat.com> - 1.4-7
- CVE-2011-1781, CVE-2011-1769
* Wed May  4 2011 Dennis Gilmore <dennis at ausil.us> - 1.4-6
- no crash on arm
* Sun Feb 13 2011 Dennis Gilmore <dennis at ausil.us> - 1.4-5
- no crash on sparc
* Wed Feb  9 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.4-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #703972 - CVE-2011-1781 systemtap: divide by zero stack unwinding flaw
        https://bugzilla.redhat.com/show_bug.cgi?id=703972
  [ 2 ] Bug #702687 - CVE-2011-1769 systemtap: does not guard against DWARF operations div-by-zero errors, which can cause a kernel panic
        https://bugzilla.redhat.com/show_bug.cgi?id=702687
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update systemtap' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list