Vulnerability CVE-2023-33204: Information

Description

sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: May 18, 2023
Modified: Nov. 7, 2023
Error type identifier: CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
sysstatsisyphus12.7.2-alt212.7.5-alt1ALT-PU-2023-1964-1322645Fixed
sysstatsisyphus_e2k12.7.2-alt212.7.5-alt1ALT-PU-2023-3908-1-Fixed
sysstatsisyphus_riscv6412.7.2-alt212.7.5-alt1ALT-PU-2023-3952-1-Fixed
sysstatp1012.7.4-alt112.7.4-alt1ALT-PU-2023-2077-1323594Fixed
sysstatp10_e2k12.7.4-alt112.7.4-alt1ALT-PU-2023-7078-1-Fixed
sysstatc10f112.7.2-alt212.7.2-alt2ALT-PU-2023-2079-1323363Fixed
sysstatc9f212.7.2-alt212.7.2-alt2ALT-PU-2023-2078-1323361Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:sysstat_project:sysstat:*:*:*:*:*:*:*:*
      End including
      12.7.2

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*