SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs context variable access.
Vector
LOCAL
Complexity
HIGH
Authentication
NONE
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL
Moodle 2.4.4
Moodle 2.5
Moodle 2.5.1
Moodle 2.5.2
Moodle 2.4.6
Moodle 2.4.9
Moodle 2.5.3
Moodle 2.5.6
Moodle 2.4.11
Moodle 2.5.7
Moodle 2.4.10
Moodle 2.5.4
Moodle 2.5.5
Moodle 2.4.2
Moodle 2.3.2
Moodle 2.3.5
Moodle 2.3.4
Moodle 2.3.3
Moodle 2.3.9
Moodle 2.4
Moodle 2.4.1
Moodle 2.4.5
Moodle 2.3.11
Moodle 2.3.8
Moodle 2.4.3
Moodle 2.4.8
Moodle 2.3.7
Moodle 2.4.7
Moodle 2.3.6