ALT-PU-2023-1964-2
Closed vulnerabilities
Published: 2025-02-03
Modified: 2025-05-05
Modified: 2025-05-05
BDU:2025-00980
Уязвимость компонента common.c утилиты для измерения и анализа производительности системы sysstat, позволяющая нарушителю выполнить произвольный код
Severity: HIGH (7.8)Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: HIGH (7.2)Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
References:
Published: 2023-05-18
Modified: 2025-11-03
Modified: 2025-11-03
CVE-2023-33204
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Severity: HIGH (7.8)Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- https://github.com/sysstat/sysstat/pull/360
- https://lists.debian.org/debian-lts-announce/2023/05/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7UUEKMNDMC6RZTI4O367ZD2YKCOX5THX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NUBFX3UNOSM7KFUIB3J32ASYT5ZRXJQV/
- https://github.com/sysstat/sysstat/pull/360
- https://lists.debian.org/debian-lts-announce/2023/05/msg00026.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7UUEKMNDMC6RZTI4O367ZD2YKCOX5THX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NUBFX3UNOSM7KFUIB3J32ASYT5ZRXJQV/
