SB2019090922 - Integer overflow in sysstat
Published: September 9, 2019 Updated: July 17, 2020
Security Bulletin ID
SB2019090922
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2019-16167)
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
Remediation
Install update from vendor's website.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00068.html
- https://github.com/sysstat/sysstat/compare/v12.1.5...v12.1.6
- https://github.com/sysstat/sysstat/issues/230
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RVSMKUPWIGQYX4G5LZXL7ZBJN3KY6RM3/
- https://usn.ubuntu.com/4242-1/