First published: Thu May 18 2023(Updated: )
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysstat Project Sysstat | <=12.7.2 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-33204.
The severity of CVE-2023-33204 is high with a CVSS score of 7.8.
The affected software for CVE-2023-33204 includes sysstat versions up to and including 12.7.2, Fedora versions 37 and 38, and Debian Linux version 10.0.
CVE-2023-33204 is caused by a multiplication integer overflow in the check_overflow function in common.c.
Yes, you can find references for CVE-2023-33204 at the following links: [Reference 1](https://github.com/sysstat/sysstat/pull/360), [Reference 2](https://lists.debian.org/debian-lts-announce/2023/05/msg00026.html), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7UUEKMNDMC6RZTI4O367ZD2YKCOX5THX/)