The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.
- https://bugs.gentoo.org/show_bug.cgi?id=188808
- https://github.com/lucassbeiler/linux_hardening_arsenal