Bugzilla – Bug 50103
VUL-0: CVE-2004-0108: sysstat: insecure tmp file handling
Last modified: 2021-10-11 13:54:55 UTC
Hi, the following was posted on vendor-sec. ---------- Forwarded message ---------- Date: Tue, 24 Feb 2004 12:27:52 +0000 (GMT) From: Mark J Cox <mjc@redhat.com> To: vendor-sec@lst.de Subject: [vendor-sec] CAN-2004-0108 sysstat (isag) vulnerability Alan Cox was looking at our sysstat packages and noticed that the version of isag included with sysstat contains a minor temporary file vulnerability. We've allocated CVE name CAN-2004-0108 to this issue. I've included the patch written by Nils Philippsen against 5.0.1. I've informed the sysstat and isag upstream vendors and suggested that we embargo this issue until 1400UTC on March 10th. We also found that our own sysstat rpms contained another vulnerability in our post/trigger scripts. This isn't a flaw in the upstream sysstat packages; we will correct this at the same time (let me know if anyone here shipping rpm updates has the same issue). Thanks, Mark -- Mark J Cox / Red Hat Security Response Team
<!-- SBZ_reproduce --> -
Created attachment 16218 [details] sysstat-5.0.1-mktemp.patch
Created attachment 16221 [details] patchinfo.sysstat
Created attachment 16222 [details] patchinfo-box.sysstat
Created attachment 16316 [details] mail
Created attachment 16317 [details] mail attachement
fixed except for stable (I'll do this ASAP)
Ok, please reassign to me if you are done.
Is this fixed for STABLE now?
submitted together with another fix
*** Bug 53411 has been marked as a duplicate of this bug. ***
packages approved a few minutes ago.
CVE-2004-0108: CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P)