Oval Definition:oval:com.redhat.rhsa:def:20091619
Revision Date:2009-11-30Version:641
Title:RHSA-2009:1619: dstat security update (Moderate)
Description:Dstat is a versatile replacement for the vmstat, iostat, and netstat tools. Dstat can be used for performance tuning tests, benchmarks, and troubleshooting.

  • Robert Buchholz of the Gentoo Security Team reported a flaw in the Python module search path used in dstat. If a local attacker could trick a local user into running dstat from a directory containing a Python script that is named like an importable module, they could execute arbitrary code with the privileges of the user running dstat. (CVE-2009-3894)

    All dstat users should upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-3894
    RHSA-2009:1619
    RHSA-2009:1619-01
    RHSA-2009:1619-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND dstat is earlier than 0:0.6.6-3.el5_4.1
  • AND dstat is signed with Red Hat redhatrelease2 key
  • BACK