[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2009:1619 -- centos 5 x86_64 dstat

ID: oval:org.secpod.oval:def:202219Date: (C)2012-01-31   (M)2022-10-10
Class: PATCHFamily: unix




Dstat is a versatile replacement for the vmstat, iostat, and netstat tools. Dstat can be used for performance tuning tests, benchmarks, and troubleshooting. Robert Buchholz of the Gentoo Security Team reported a flaw in the Python module search path used in dstat. If a local attacker could trick a local user into running dstat from a directory containing a Python script that is named like an importable module, they could execute arbitrary code with the privileges of the user running dstat. All dstat users should upgrade to this updated package, which contains a backported patch to correct this issue.

Platform:
CentOS 5
Product:
dstat
Reference:
CESA-2009:1619
CVE-2009-3894
CVE    1
CVE-2009-3894
CPE    2
cpe:/a:dag_wieers:dstat
cpe:/o:centos:centos:5

© SecPod Technologies