The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sysstat | Sysstat | 5.1.2 (including) | 5.1.2 (including) |
Sysstat | Sysstat | 5.1.3 (including) | 5.1.3 (including) |
Sysstat | Sysstat | 5.1.4 (including) | 5.1.4 (including) |
Sysstat | Sysstat | 5.1.5 (including) | 5.1.5 (including) |
Sysstat | Sysstat | 6.0.0 (including) | 6.0.0 (including) |
Sysstat | Sysstat | 6.0.1 (including) | 6.0.1 (including) |
Sysstat | Sysstat | 6.0.2 (including) | 6.0.2 (including) |
Sysstat | Sysstat | 6.0.3 (including) | 6.0.3 (including) |
Sysstat | Sysstat | 6.0.4 (including) | 6.0.4 (including) |
Sysstat | Sysstat | 6.0.5 (including) | 6.0.5 (including) |
Sysstat | Sysstat | 7.0.0 (including) | 7.0.0 (including) |
Sysstat | Sysstat | 7.0.1 (including) | 7.0.1 (including) |
Sysstat | Sysstat | 7.0.2 (including) | 7.0.2 (including) |
Sysstat | Sysstat | 7.0.3 (including) | 7.0.3 (including) |
Sysstat | Sysstat | 7.0.4 (including) | 7.0.4 (including) |
Sysstat | Sysstat | 7.1.1 (including) | 7.1.1 (including) |
Sysstat | Sysstat | 7.1.2 (including) | 7.1.2 (including) |
Sysstat | Sysstat | 7.1.3 (including) | 7.1.3 (including) |
Sysstat | Sysstat | 7.1.4 (including) | 7.1.4 (including) |
Sysstat | Sysstat | 7.1.5 (including) | 7.1.5 (including) |
Sysstat | Sysstat | 7.1.6 (including) | 7.1.6 (including) |
Red Hat Enterprise Linux 5 | RedHat | sysstat-0:7.0.2-11.el5 | * |