USN-6145-1
Dashboard / Vulnerabilities / USN-6145-1
USN-6145-1
Summary: sysstat vulnerabilities
Details: It was discovered that Sysstat incorrectly handled certain arithmetic multiplications. An attacker could use this issue to cause Sysstat to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue was only fixed for Ubuntu 16.04 LTS. (CVE-2022-39377) It was discovered that Sysstat incorrectly handled certain arithmetic multiplications in 64-bit systems, as a result of an incomplete fix for CVE-2022-39377. An attacker could use this issue to cause Sysstat to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-33204)
References: https://ubuntu.com/security/notices/USN-6145-1, https://ubuntu.com/security/CVE-2022-39377, https://ubuntu.com/security/CVE-2023-33204
Affected packages
Package
Name: sysstat
Purl: pkg:deb/ubuntu/sysstat?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
