[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2009:1619-01 -- Redhat dstat

ID: oval:org.secpod.oval:def:500627Date: (C)2012-01-31   (M)2021-07-09
Class: PATCHFamily: unix




Dstat is a versatile replacement for the vmstat, iostat, and netstat tools. Dstat can be used for performance tuning tests, benchmarks, and troubleshooting. Robert Buchholz of the Gentoo Security Team reported a flaw in the Python module search path used in dstat. If a local attacker could trick a local user into running dstat from a directory containing a Python script that is named like an importable module, they could execute arbitrary code with the privileges of the user running dstat. All dstat users should upgrade to this updated package, which contains a backported patch to correct this issue.

Platform:
Red Hat Enterprise Linux 5
Product:
dstat
Reference:
RHSA-2009:1619-01
CVE-2009-3894
CVE    1
CVE-2009-3894
CPE    2
cpe:/o:redhat:enterprise_linux:5
cpe:/a:dag_wieers:dstat

© SecPod Technologies