Alan Cox discovered that the isag utility (which graphically displays
data collected by the sysstat tools), creates a temporary file without
taking proper precautions. This vulnerability could allow a local
attacker to overwrite files with the privileges of the user invoking
isag.
For the current stable distribution (woody) this problem has been
fixed in version 5.0.1-1.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you update your sysstat package.
CPE | Name | Operator | Version |
---|---|---|---|
sysstat | eq | 4.0.4-1woody2 |