vendor:
SystemTap
by:
7.5
CVSS
HIGH
Remote Command-Injection
78
CWE
Product Name: SystemTap
Affected Version From:
Affected Version To: SystemTap 1.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
SystemTap Remote Command-Injection Vulnerability
SystemTap is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data. Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
Mitigation:
Upgrade to SystemTap 1.1 or later to address this vulnerability.