Vulnerability Name:

CVE-2007-3852 (CCN-36045)

Assigned:2007-08-10
Published:2007-08-10
Updated:2023-02-13
Summary:The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.
CVSS v3 Severity:8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
3.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.2 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
1.9 Low (REDHAT CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N)
1.5 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-377
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2007-3852

Source: CCN
Type: sysstat Web site
SYSSTAT

Source: CCN
Type: RHSA-2011-1005
Low: sysstat security, bug fix, and enhancement update

Source: CCN
Type: SA26527
Sysstat systat.in Insecure Temporary Files

Source: CCN
Type: OSVDB ID: 39709
Sysstat systat.in /tmp/sysstat.run Symlink Local Privilege Escalation

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: CCN
Type: BID-25380
Sysstat Insecure Temporary File Creation Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Gentoo Bugzilla Bug 188808
>=app-admin/sysstat-7.1 Insecure temporary file usage (CVE-2007-3852)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
sysstat-init-privilege-escalation(36045)

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20073852
    V
    CVE-2007-3852
    2022-09-02
    oval:org.opensuse.security:def:113475
    P
    sysstat-12.4.3-3.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26219
    P
    Security update for apache2 (Important) (in QA)
    2022-01-10
    oval:org.opensuse.security:def:31328
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31720
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:31307
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:32223
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:32221
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:26166
    P
    Security update for php74 (Moderate)
    2021-11-18
    oval:org.opensuse.security:def:42235
    P
    Security update for qemu (Important)
    2021-11-03
    oval:org.opensuse.security:def:31296
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:31295
    P
    Security update for transfig (Important)
    2021-10-29
    oval:org.opensuse.security:def:26154
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:106872
    P
    sysstat-12.4.3-3.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26137
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:33003
    P
    Security update for postgresql13 (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:32172
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:26110
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:31662
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:26096
    P
    Security update for php72 (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:32136
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:32116
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:31196
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:36303
    P
    sysstat-8.1.5-7.50.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42710
    P
    sysstat-8.1.5-7.50.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32115
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:26057
    P
    Security update for libX11 (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:26056
    P
    Security update for curl (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:32079
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32071
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:31605
    P
    Security update for xorg-x11-server (Important)
    2021-04-14
    oval:org.opensuse.security:def:31749
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:32282
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:26194
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:32260
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:31724
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:32964
    P
    Security update for MozillaFirefox (Important)
    2021-01-29
    oval:org.opensuse.security:def:32010
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:35828
    P
    sysstat-8.1.5-7.32.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36040
    P
    sysstat-8.1.5-7.45.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25969
    P
    Security update for xen (Important)
    2020-12-03
    oval:org.opensuse.security:def:42447
    P
    sysstat-8.1.5-7.45.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35642
    P
    sysstat-8.1.5-7.9.56 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42049
    P
    sysstat-8.1.5-7.9.56 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25390
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25720
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:26792
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25590
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25874
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26365
    P
    Security update of chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25852
    P
    Security update for flash-playerqemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:26429
    P
    Security update for keepalived (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26584
    P
    libdrm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31564
    P
    Security update for squid3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31864
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32607
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32753
    P
    nagios-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31507
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31816
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32326
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31769
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31987
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32379
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32545
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25193
    P
    Security update for ed (Low)
    2020-12-01
    oval:org.opensuse.security:def:25397
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:25770
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25925
    P
    Security update for pcre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25454
    P
    Security update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25804
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26827
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25601
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25931
    P
    Security update for libcares2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26268
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27003
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25853
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26482
    P
    Security update for ffmpeg-4 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26628
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31110
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:31886
    P
    Security update for ed (Low)
    2020-12-01
    oval:org.opensuse.security:def:31381
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32049
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32792
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31518
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:31873
    P
    Security update for cvs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31770
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:32435
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32589
    P
    pam_krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25194
    P
    Security update for adns (Important)
    2020-12-01
    oval:org.opensuse.security:def:25478
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25823
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25378
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25582
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25955
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25665
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:26015
    P
    Security update for libplist (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26307
    P
    Security update for conntrack-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27038
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25864
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26531
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27266
    P
    perl-libwww-perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31111
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31420
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31776
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31930
    P
    Security update for glib2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31513
    P
    Security update for quagga
    2020-12-01
    oval:org.opensuse.security:def:31905
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31592
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31960
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31781
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32484
    P
    PackageKit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33227
    P
    pcsc-lite on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25205
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:25535
    P
    Security update for audiofile (Low)
    2020-12-01
    oval:org.opensuse.security:def:25872
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26607
    P
    libvorbis on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25379
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25663
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26008
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25589
    P
    Security update for zabbix (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25793
    P
    Security update for icedtea-web (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26321
    P
    Security update for kcoreaddons (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25928
    P
    Security update for pcre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26278
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26570
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27301
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31122
    P
    Security update for kvm
    2020-12-01
    oval:org.opensuse.security:def:31477
    P
    Security update for puppet (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31825
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:32568
    P
    libsnmp15-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31961
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:31506
    P
    Security update for python27 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31855
    P
    Security update for crash (Low)
    2020-12-01
    oval:org.opensuse.security:def:32523
    P
    gnutls on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33266
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25269
    P
    Security update for libpng12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25619
    P
    Security update for libmspack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25911
    P
    Security update for gstreamer-plugins-base (Low)
    2020-12-01
    oval:org.opensuse.security:def:26642
    P
    sysstat on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:23324
    P
    ELSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)
    2014-05-26
    oval:org.mitre.oval:def:22033
    P
    RHSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)
    2014-02-24
    oval:com.redhat.rhsa:def:20111005
    P
    RHSA-2011:1005: sysstat security, bug fix, and enhancement update (Low)
    2011-07-21
    BACK