CVE-2007-3852
Summary
| CVE | CVE-2007-3852 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-08-14 18:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sysstat | Sysstat | 5.1.2 | All | All | All |
| Application | Sysstat | Sysstat | 5.1.3 | All | All | All |
| Application | Sysstat | Sysstat | 5.1.4 | All | All | All |
| Application | Sysstat | Sysstat | 5.1.5 | All | All | All |
| Application | Sysstat | Sysstat | 6.0.0 | All | All | All |
| Application | Sysstat | Sysstat | 6.0.1 | All | All | All |
| Application | Sysstat | Sysstat | 6.0.2 | All | All | All |
| Application | Sysstat | Sysstat | 6.0.3 | All | All | All |
| Application | Sysstat | Sysstat | 6.0.4 | All | All | All |
| Application | Sysstat | Sysstat | 6.0.5 | All | All | All |
| Application | Sysstat | Sysstat | 7.0.0 | All | All | All |
| Application | Sysstat | Sysstat | 7.0.1 | All | All | All |
| Application | Sysstat | Sysstat | 7.0.2 | All | All | All |
| Application | Sysstat | Sysstat | 7.0.3 | All | All | All |
| Application | Sysstat | Sysstat | 7.0.4 | All | All | All |
| Application | Sysstat | Sysstat | 7.1.1 | All | All | All |
| Application | Sysstat | Sysstat | 7.1.2 | All | All | All |
| Application | Sysstat | Sysstat | 7.1.3 | All | All | All |
| Application | Sysstat | Sysstat | 7.1.4 | All | All | All |
| Application | Sysstat | Sysstat | 7.1.5 | All | All | All |
| Application | Sysstat | Sysstat | 7.1.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sysstat systat.in Insecure Temporary Files - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/39709 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Sysstat Insecure Temporary File Creation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 188808 – >=app-admin/sysstat-7.1 Insecure temporary file usage (CVE-2007-3852) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2007-3852 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 251200 – (CVE-2007-3852) CVE-2007-3852 sysstat insecure temporary file usage | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-05-12 | Joshua Bressers | This issue did not affect the versions of sysstat as shipped with Red Hat Enterprise Linux 2.1, 3, or 4. For Red Hat Enterprise Linux 5, Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=251200 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.