Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2011:1005 - Security Advisory
Issued:
2011-07-21
Updated:
2011-07-21

RHSA-2011:1005 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Low: sysstat security, bug fix, and enhancement update

Type/Severity

Security Advisory: Low

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An updated sysstat package that fixes one security issue, various bugs, and
adds one enhancement is now available for Red Hat Enterprise Linux 5.

The Red Hat Security Response Team has rated this update as having low
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

Description

The sysstat package contains a set of utilities which enable system
monitoring of disks, network, and other I/O activity.

It was found that the sysstat initscript created a temporary file in an
insecure way. A local attacker could use this flaw to create arbitrary
files via a symbolic link attack. (CVE-2007-3852)

This update fixes the following bugs:

  • On systems under heavy load, the sadc utility would sometimes output the

following error message if a write() call was unable to write all of the
requested input:

"Cannot write data to system activity file: Success."

In this updated package, the sadc utility tries to write the remaining
input, resolving this issue. (BZ#454617)

  • On the Itanium architecture, the "sar -I" command provided incorrect

information about the interrupt statistics of the system. With this update,
the "sar -I" command has been disabled for this architecture, preventing
this bug. (BZ#468340)

  • Previously, the "iostat -n" command used invalid data to create

statistics for read and write operations. With this update, the data source
for these statistics has been fixed, and the iostat utility now returns
correct information. (BZ#484439)

  • The "sar -d" command used to output invalid data about block devices.

With this update, the sar utility recognizes disk registration and disk
overflow statistics properly, and only correct and relevant data is now
displayed. (BZ#517490)

  • Previously, the sar utility set the maximum number of days to be logged

in one month too high. Consequently, data from a month was appended to
data from the preceding month. With this update, the maximum number of days
has been set to 25, and data from a month now correctly replaces data from
the preceding month. (BZ#578929)

  • In previous versions of the iostat utility, the number of NFS mount

points was hard-coded. Consequently, various issues occurred while iostat
was running and NFS mount points were mounted or unmounted; certain values
in iostat reports overflowed and some mount points were not reported at
all. With this update, iostat properly recognizes when an NFS mount point
mounts or unmounts, fixing these issues. (BZ#675058, BZ#706095, BZ#694767)

  • When a device name was longer than 13 characters, the iostat utility

printed a redundant new line character, making its output less readable.
This bug has been fixed and now, no extra characters are printed if a long
device name occurs in iostat output. (BZ#604637)

  • Previously, if kernel interrupt counters overflowed, the sar utility

provided confusing output. This bug has been fixed and the sum of
interrupts is now reported correctly. (BZ#622557)

  • When some processors were disabled on a multi-processor system, the sar

utility sometimes failed to provide information about the CPU activity.
With this update, the uptime of a single processor is used to compute the
statistics, rather than the total uptime of all processors, and this bug no
longer occurs. (BZ#630559)

  • Previously, the mpstat utility wrongly interpreted data about processors

in the system. Consequently, it reported a processor that did not exist.
This bug has been fixed and non-existent CPUs are no longer reported by
mpstat. (BZ#579409)

  • Previously, there was no easy way to enable the collection of statistics

about disks and interrupts. Now, the SADC_OPTIONS variable can be used to
set parameters for the sadc utility, fixing this bug. (BZ#598794)

  • The read_uptime() function failed to close its open file upon exit. A

patch has been provided to fix this bug. (BZ#696672)

This update also adds the following enhancement:

  • With this update, the cifsiostat utility has been added to the sysstat

package to provide CIFS (Common Internet File System) mount point I/O
statistics. (BZ#591530)

All sysstat users are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add this
enhancement.

Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

Affected Products

  • Red Hat Enterprise Linux Server 5 x86_64
  • Red Hat Enterprise Linux Server 5 ia64
  • Red Hat Enterprise Linux Server 5 i386
  • Red Hat Enterprise Linux Workstation 5 x86_64
  • Red Hat Enterprise Linux Workstation 5 i386
  • Red Hat Enterprise Linux Desktop 5 x86_64
  • Red Hat Enterprise Linux Desktop 5 i386
  • Red Hat Enterprise Linux for IBM z Systems 5 s390x
  • Red Hat Enterprise Linux for Power, big endian 5 ppc
  • Red Hat Enterprise Linux Server from RHUI 5 x86_64
  • Red Hat Enterprise Linux Server from RHUI 5 i386

Fixes

  • BZ - 251200 - CVE-2007-3852 sysstat insecure temporary file usage
  • BZ - 454617 - [RHEL5] Though function write() executed sucessful, sadc end with an error.
  • BZ - 484439 - iostat -n enhancement not report NFS client stats correctly
  • BZ - 517490 - The 'sar -d ' command outputs invalid data
  • BZ - 578929 - March sar data was appended to February data
  • BZ - 579409 - The sysstat's programs such as mpstat shows one extra cpu.
  • BZ - 598794 - Enable parametrization of sadc arguments
  • BZ - 604637 - extraneous newline in iostat report for long device names
  • BZ - 622557 - sar interrupt count goes backward
  • BZ - 630559 - 'sar -P ALL -f xxxx ' does not display activity information.
  • BZ - 675058 - iostat: bogus value appears when device is unmounted/mounted
  • BZ - 694767 - iostat doesn't report statistics for shares with long names
  • BZ - 696672 - Resource leak
  • BZ - 706095 - iostat -n - values in output overflows

CVEs

  • CVE-2007-3852

References

  • https://access.redhat.com/security/updates/classification/#low
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 5

SRPM
sysstat-7.0.2-11.el5.src.rpm SHA-256: fd36c999a74623c18ef7341681474d84aaa2c78bce9d194aaaafca90673ea4ea
x86_64
sysstat-7.0.2-11.el5.x86_64.rpm SHA-256: abf54df5b37ee440d42ccc9014aff1de81837263a4439b3abea25742ef8c56a5
ia64
sysstat-7.0.2-11.el5.ia64.rpm SHA-256: 6587e35cfb9c7cf1747a876587298fa0d972bf9a35e03f028fa641185313ca66
i386
sysstat-7.0.2-11.el5.i386.rpm SHA-256: 9b65fde46bf1725b90c0c5e2f26e8f98655393c0332e1b7929c08830c852f680

Red Hat Enterprise Linux Workstation 5

SRPM
sysstat-7.0.2-11.el5.src.rpm SHA-256: fd36c999a74623c18ef7341681474d84aaa2c78bce9d194aaaafca90673ea4ea
x86_64
sysstat-7.0.2-11.el5.x86_64.rpm SHA-256: abf54df5b37ee440d42ccc9014aff1de81837263a4439b3abea25742ef8c56a5
i386
sysstat-7.0.2-11.el5.i386.rpm SHA-256: 9b65fde46bf1725b90c0c5e2f26e8f98655393c0332e1b7929c08830c852f680

Red Hat Enterprise Linux Desktop 5

SRPM
sysstat-7.0.2-11.el5.src.rpm SHA-256: fd36c999a74623c18ef7341681474d84aaa2c78bce9d194aaaafca90673ea4ea
x86_64
sysstat-7.0.2-11.el5.x86_64.rpm SHA-256: abf54df5b37ee440d42ccc9014aff1de81837263a4439b3abea25742ef8c56a5
i386
sysstat-7.0.2-11.el5.i386.rpm SHA-256: 9b65fde46bf1725b90c0c5e2f26e8f98655393c0332e1b7929c08830c852f680

Red Hat Enterprise Linux for IBM z Systems 5

SRPM
sysstat-7.0.2-11.el5.src.rpm SHA-256: fd36c999a74623c18ef7341681474d84aaa2c78bce9d194aaaafca90673ea4ea
s390x
sysstat-7.0.2-11.el5.s390x.rpm SHA-256: 10a551009c0be10b02241506f1fff22ba5821a6a0c3d30ba81671b06aca8689d

Red Hat Enterprise Linux for Power, big endian 5

SRPM
sysstat-7.0.2-11.el5.src.rpm SHA-256: fd36c999a74623c18ef7341681474d84aaa2c78bce9d194aaaafca90673ea4ea
ppc
sysstat-7.0.2-11.el5.ppc.rpm SHA-256: e60caca86a828e82b331c4819075394c1c6efe963bef828be7d056d683eb379f

Red Hat Enterprise Linux Server from RHUI 5

SRPM
sysstat-7.0.2-11.el5.src.rpm SHA-256: fd36c999a74623c18ef7341681474d84aaa2c78bce9d194aaaafca90673ea4ea
x86_64
sysstat-7.0.2-11.el5.x86_64.rpm SHA-256: abf54df5b37ee440d42ccc9014aff1de81837263a4439b3abea25742ef8c56a5
i386
sysstat-7.0.2-11.el5.i386.rpm SHA-256: 9b65fde46bf1725b90c0c5e2f26e8f98655393c0332e1b7929c08830c852f680

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility