CVE-2023-33204: Integer Overflow
sysstat through 12.7.2 allows a multiplication integer overflow in checkoverflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this sysstat issue?
The vulnerability ID is CVE-2023-33204.
What is the severity of CVE-2023-33204?
The severity of CVE-2023-33204 is high with a CVSS score of 7.8.
What is the affected software for CVE-2023-33204?
The affected software for CVE-2023-33204 includes sysstat versions up to and including 12.7.2, Fedora versions 37 and 38, and Debian Linux version 10.0.
What is the root cause of CVE-2023-33204?
CVE-2023-33204 is caused by a multiplication integer overflow in the check_overflow function in common.c.
Are there any references for CVE-2023-33204?
Yes, you can find references for CVE-2023-33204 at the following links: [Reference 1](https://github.com/sysstat/sysstat/pull/360), [Reference 2](https://lists.debian.org/debian-lts-announce/2023/05/msg00026.html), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7UUEKMNDMC6RZTI4O367ZD2YKCOX5THX/)