First published: Tue Aug 14 2007(Updated: )
The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sysstat | =6.0.2 | |
Sysstat | =7.1.5 | |
Sysstat | =7.0.3 | |
Sysstat | =7.1.4 | |
Sysstat | =7.0.1 | |
Sysstat | =6.0.1 | |
Sysstat | =5.1.2 | |
Sysstat | =7.0.0 | |
Sysstat | =5.1.4 | |
Sysstat | =6.0.5 | |
Sysstat | =7.0.2 | |
Sysstat | =6.0.3 | |
Sysstat | =5.1.5 | |
Sysstat | =6.0.0 | |
Sysstat | =7.1.1 | |
Sysstat | =7.0.4 | |
Sysstat | =7.1.2 | |
Sysstat | =6.0.4 | |
Sysstat | =7.1.3 | |
Sysstat | =5.1.3 | |
Sysstat | =7.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3852 is classified as high severity due to its potential for local users to execute arbitrary code.
To fix CVE-2007-3852, upgrade sysstat to version 7.1.7 or later, where the issue has been resolved.
CVE-2007-3852 affects sysstat versions 5.1.2 to 7.1.6.
Exploitation of CVE-2007-3852 can lead to arbitrary code execution, compromising system integrity.
CVE-2007-3852 can be exploited by any local user who has access to the affected sysstat versions.