Lucene search

K
gentooGentoo FoundationGLSA-202211-07
HistoryNov 22, 2022 - 12:00 a.m.

sysstat: Arbitrary Code Execution

2022-11-2200:00:00
Gentoo Foundation
security.gentoo.org
12
sysstat
linux
integer overflow
arbitrary code execution
upgrade

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

76.6%

Background

sysstat is a package containing a number of performance monitoring utilities for Linux, including sar, mpstat, iostat and sa tools.

Description

On 32 bit systems, an integer overflow can be triggered when displaying activity data files.

Impact

Arbitrary code execution can be achieved via sufficiently crafted malicious input.

Workaround

There is no known workaround at this time.

Resolution

All sysstat users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-admin/sysstat-12.6.2-r1"
OSVersionArchitecturePackageVersionFilename
Gentooanyallapp-admin/sysstat< 12.6.2-r1UNKNOWN

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

76.6%