[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-39377Date: (C)2022-11-10   (M)2024-02-06


sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated for the buffer representing system activities. This issue may lead to Remote Code Execution (RCE). This issue has been patched in version 12.7.1.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score :
Exploit Score: 1.8Exploit Score:
Impact Score: 5.9Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: NONEAuthentication:
User Interaction: REQUIREDConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: HIGHAvailability:
Integrity: HIGH 
Availability: HIGH 
  
Reference:
FEDORA-2022-5adda2d05f
FEDORA-2022-9f3af921a5
FEDORA-2022-dbe48a4bc7
GLSA-202211-07
https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html
https://github.com/sysstat/sysstat/security/advisories/GHSA-q8r6-g56f-9w7x

CWE    1
CWE-120
OVAL    14
oval:org.secpod.oval:def:86539
oval:org.secpod.oval:def:507683
oval:org.secpod.oval:def:507733
oval:org.secpod.oval:def:2501094
...

© SecPod Technologies