Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19725

Опубликовано: 09 дек. 2019
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

A double-free vulnerability was found in sysstat in the way the sadf command processes the contents of data files created by the sar command. Saved binary data files with support for extra_desc structures may be vulnerable to this flaw. A remote attacker could exploit this flaw by creating a specially crafted file with malformed data that, when loaded by a victim, would cause the application to potentially execute arbitrary code.

Отчет

This flaw does not affect the versions of sysstat as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8 as they do not include support for extra_desc structures in binary data files created by the sar command. Consequently, they do not include the vulnerable code leading to the double free vulnerability either.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sysstatNot affected
Red Hat Enterprise Linux 6sysstatNot affected
Red Hat Enterprise Linux 7sysstatNot affected
Red Hat Enterprise Linux 8sysstatNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-672
https://bugzilla.redhat.com/show_bug.cgi?id=1784740sysstat: double free in check_file_actlst() in sa_common.c may lead to arbitrary code execution

EPSS

Процентиль: 42%
0.00198
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

CVSS3: 9.8
nvd
больше 5 лет назад

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

CVSS3: 9.8
debian
больше 5 лет назад

sysstat through 12.2.0 has a double free in check_file_actlst in sa_co ...

suse-cvrf
около 5 лет назад

Security update for sysstat

suse-cvrf
около 5 лет назад

Security update for sysstat

EPSS

Процентиль: 42%
0.00198
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2019-19725