Back

MEDIUM

sysstat insecure temporary file usage

Published Aug 14, 2007

Description

The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of sysstat as shipped with Red Hat Enterprise Linux 4. This issue has been addressed in Red Hat Enterprise Linux 5 via RHSA-2011:1005 advisory.

Metrics

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 14, 2007
Updated Aug 7, 2024
Reserved Jul 18, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Aug 10, 2007