Integer overflow in sysstat - CVE-2023-33204

 

Integer overflow in sysstat - CVE-2023-33204

Published: June 8, 2023


Vulnerability identifier: #VU77081
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33204
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the check_overflow() function in common.c. A remote attacker can trigger an integer overflow and execute arbitrary code on the target system.

Note, the vulnerability exists due to incomplete fix for #VU69196 (CVE-2022-39377).


Affected software

sysstat
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
sysstat (Ubuntu package)
sysstat (Red Hat package)
sysstat-doc
sysstat
sysstat-isag
sysstat-debuginfo
sysstat-debugsource
app-admin/sysstat
VMware Tanzu Operations Manager

How to mitigate CVE-2023-33204

Install updates from vendor's website.

sysstat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 12.2.0-2ubuntu0.3, 12.5.2-2ubuntu0.2, 12.5.6-1ubuntu0.2, 12.6.1-1ubuntu0.1
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.12
sysstat (Red Hat package) - addressed in versions 11.7.3-11.el8, 12.5.4-7.el9
sysstat-doc - update to 11.7.3-11.0.1
sysstat - update to 11.7.3-11.0.1
sysstat-isag - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debuginfo - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debugsource - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debuginfo - update to 12.2.1-6
sysstat-debugsource - update to 12.2.1-6
sysstat - update to 12.2.1-6
sysstat - update to 12.5.6-1
app-admin/sysstat - update to 12.6.2-r1
sysstat - addressed in versions 12.6.2-2.fc37, 12.7.4-1.fc38

External References

Related Security Bulletins