CVE-2023-33204

Name
CVE-2023-33204
Description
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/sysstat/sysstat/pull/360
MLIST https://lists.debian.org/debian-lts-announce/2023/05/msg00026.html
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NUBFX3UNOSM7KFUIB3J32ASYT5ZRXJQV/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7UUEKMNDMC6RZTI4O367ZD2YKCOX5THX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NUBFX3UNOSM7KFUIB3J32ASYT5ZRXJQV/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7UUEKMNDMC6RZTI4O367ZD2YKCOX5THX/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sysstat_project:sysstat:*:*:*:*:*:*:*:* sysstat >= None <= 12.7.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sysstat edge-community 12.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
sysstat 3.18-community 12.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
sysstat 3.19-community 12.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
sysstat 3.20-community 12.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable