Bug 25804 - sysstat new security issue CVE-2019-16167
Summary: sysstat new security issue CVE-2019-16167
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-12-03 18:58 CET by David Walser
Modified: 2019-12-06 15:17 CET (History)
4 users (show)

See Also:
Source RPM: sysstat-12.1.4-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-12-03 18:58:52 CET
openSUSE has issued an advisory on October 28:
https://lists.opensuse.org/opensuse-updates/2019-10/msg00168.html

The issue is fixed upstream in 12.1.6.
Comment 1 David GEIGER 2019-12-04 07:44:49 CET
Done!
Comment 2 David Walser 2019-12-04 13:46:04 CET
Advisory:
========================

Updated sysstat package fixes security vulnerability:

Memory corruption due to an integer overflow (CVE-2019-16167).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16167
https://lists.opensuse.org/opensuse-updates/2019-10/msg00168.html
========================

Updated packages in core/updates_testing:
========================
sysstat-12.1.6-1.mga7

from sysstat-12.1.6-1.mga7.src.rpm

CC: (none) => geiger.david68210
Assignee: geiger.david68210 => qa-bugs

Comment 3 PC LX 2019-12-06 11:37:36 CET
Installed and tested without issues.

Tested the following CLI binaries:
/usr/bin/iostat
/usr/bin/mpstat
/usr/bin/pidstat
/usr/bin/sadf
/usr/bin/sar

No issues where observed in the various tests.

Don't have CIFS or tapes so can't do a meaningful test for these CLI binaries:
/usr/bin/cifsiostat
/usr/bin/tapestat



System: Mageia 7, x86_64, Intel CPU, 2 SSD drives, 1 HDD drive, 3 USB drives.


$ uname -a
Linux marte 5.3.13-desktop-2.mga7 #1 SMP Mon Nov 25 20:30:40 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -q sysstat 
sysstat-12.1.6-1.mga7

CC: (none) => mageia
Whiteboard: (none) => MGA7-64-OK

Thomas Backlund 2019-12-06 14:32:26 CET

CC: (none) => tmb, sysadmin-bugs
Keywords: (none) => advisory, validated_update

Comment 4 Mageia Robot 2019-12-06 15:17:41 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0371.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.