First published: Wed Dec 11 2019(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysstat Project Sysstat | <=12.2.0 | |
Debian Debian Linux | =10.0 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Canonical Ubuntu Linux | =19.10 | |
debian/sysstat | 12.5.2-2 12.6.1-1 12.7.5-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19725 is a vulnerability in sysstat through 12.2.0 that allows a double free in check_file_actlst in sa_common.c.
CVE-2019-19725 has a severity rating of 9.8 (Critical).
The affected software of CVE-2019-19725 includes Sysstat Project Sysstat version up to 12.2.0, Debian Debian Linux version 10.0, and Canonical Ubuntu Linux versions 16.04, 18.04, 19.04, and 19.10.
To fix CVE-2019-19725 on Ubuntu, you can update the sysstat package to the recommended versions: 11.6.1-1ubuntu0.1 for bionic, 12.0.1-1ubuntu0.1 for disco, 12.0.6-1ubuntu0.1 for eoan, and 11.2.0-1ubuntu0.3 for xenial.
You can find more information about CVE-2019-19725 in the following references: [GitHub issue](https://github.com/sysstat/sysstat/issues/242), [Debian LTS announcement](https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html), and [Gentoo GLSA](https://security.gentoo.org/glsa/202007-22).