Vulnerability CVE-2023-33204: Information
Description
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
sysstat | sisyphus | 12.7.2-alt2 | 12.7.5-alt1 | ALT-PU-2023-1964-1 | 322645 | Fixed |
sysstat | sisyphus_e2k | 12.7.2-alt2 | 12.7.5-alt1 | ALT-PU-2023-3908-1 | - | Fixed |
sysstat | sisyphus_riscv64 | 12.7.2-alt2 | 12.7.5-alt1 | ALT-PU-2023-3952-1 | - | Fixed |
sysstat | p10 | 12.7.4-alt1 | 12.7.4-alt1 | ALT-PU-2023-2077-1 | 323594 | Fixed |
sysstat | p10_e2k | 12.7.4-alt1 | 12.7.4-alt1 | ALT-PU-2023-7078-1 | - | Fixed |
sysstat | c10f1 | 12.7.2-alt2 | 12.7.2-alt2 | ALT-PU-2023-2079-1 | 323363 | Fixed |
sysstat | c9f2 | 12.7.2-alt2 | 12.7.2-alt2 | ALT-PU-2023-2078-1 | 323361 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/sysstat/sysstat/pull/360 |
|
[debian-lts-announce] 20230527 [SECURITY] [DLA 3434-1] sysstat security update |
|
FEDORA-2023-ac947ec260 | |
FEDORA-2023-4706cef256 |