Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: 2022-0433 Moderate: Sysstat Remote Code Execution Advisory

mageia
Calendar Grey November 18, 2022
Dist Mageia Esm H88
The Mageia 8 sysstat security patch rectifies a buffer overflow vulnerability that could open doors to possible Remote Code Execution risks.
On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c

Summary

On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated for the buffer representing system activities. This issue may lead to Remote Code Execution (RCE). (CVE-2022-39377)

References

- https://bugs.mageia.org/show_bug.cgi?id=31120

- https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html

- - https://github.com/sysstat/sysstat/security/advisories/GHSA-q8r6-g56f-9w7x

- https://www.cve.org/CVERecord?id=CVE-2022-39377

Resolution

SRPMS

- 8/core/sysstat-12.5.2-1.1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 18 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0433.html
Type: security
CVE: CVE-2022-39377

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here