Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16167

Опубликовано: 03 авг. 2019
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.

An integer overflow vulnerability was found in sysstat in the way the sadf command processes the contents of data files created by the sar command. A local attacker could exploit this flaw by creating a specially crafted file with malformed data that, when loaded by a victim, causes the application to crash.

Отчет

This issue did not affect the versions of sysstat as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include the vulnerable function, which was introduced in a newer version of the package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sysstatNot affected
Red Hat Enterprise Linux 6sysstatNot affected
Red Hat Enterprise Linux 7sysstatNot affected
Red Hat Enterprise Linux 8sysstatFixedRHSA-2020:463804.11.2020
Red Hat Enterprise Linux 8.2 Extended Update SupportsysstatFixedRHSA-2022:063322.02.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1768970sysstat: memory corruption due to an integer overflow in remap_struct in sa_common.c

EPSS

Процентиль: 51%
0.0028
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.

CVSS3: 5.5
nvd
больше 6 лет назад

sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.

CVSS3: 5.5
debian
больше 6 лет назад

sysstat before 12.1.6 has memory corruption due to an Integer Overflow ...

suse-cvrf
около 6 лет назад

Security update for sysstat

suse-cvrf
около 6 лет назад

Security update for sysstat

EPSS

Процентиль: 51%
0.0028
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2019-16167