Scientific Linux Security Update : dstat on SL5.x i386/x86_64

This script is Copyright (C) 2012 Tenable Network Security, Inc.

Synopsis :

The remote Scientific Linux host is missing a security update.

Description :

CVE-2009-3894 dstat insecure module search path

Robert Buchholz of the Gentoo Security Team reported a flaw in the
Python module search path used in dstat. If a local attacker could
trick a local user into running dstat from a directory containing a
Python script that is named like an importable module, they could
execute arbitrary code with the privileges of the user running dstat.

See also :

Solution :

Update the affected dstat package.

Risk factor :

Medium / CVSS Base Score : 4.4

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 60698 ()

Bugtraq ID:

CVE ID: CVE-2009-3894