CVE-2018-1124
PoC —CVSS 3.1
7.8 high
EPSS
2%p79
Published
()
Modified
Description
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
- Vendors
- procps-ng projectcanonicaldebianredhatschneider-electricopensuse
- Products
- procps-ng, ubuntu linux, debian linux, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, struxureware data center expert, leap
- Weakness
- CWE-122, CWE-190, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.