CVE-2018-1122

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.

References

http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html

http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html

http://seclists.org/oss-sec/2018/q2/122

http://www.securityfocus.com/bid/104214

https://access.redhat.com/errata/RHSA-2019:2189

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1122

https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html

https://security.gentoo.org/glsa/201805-14

https://usn.ubuntu.com/3658-1/

https://usn.ubuntu.com/3658-3/

https://www.debian.org/security/2018/dsa-4208

https://www.exploit-db.com/exploits/44806/

https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt

Details

Source: MITRE

Published: 2018-05-23

Updated: 2019-10-03

Risk Information

CVSS v2

Base Score: 4.4

Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Tenable Plugins

View all (30 total)

IDNameProductFamilySeverity
143038RHEL 7 : procps-ng (RHSA-2020:1464)NessusRed Hat Local Security Checks
high
135090RHEL 7 : procps-ng (RHSA-2020:1265)NessusRed Hat Local Security Checks
high
134067RHEL 7 : procps-ng (RHSA-2020:0595)NessusRed Hat Local Security Checks
high
132484NewStart CGSL CORE 5.05 / MAIN 5.05 : procps-ng Vulnerability (NS-SA-2019-0252)NessusNewStart CGSL Local Security Checks
high
130334openSUSE Security Update : procps (openSUSE-2019-2379)NessusSuSE Local Security Checks
critical
130333openSUSE Security Update : procps (openSUSE-2019-2376)NessusSuSE Local Security Checks
critical
130229Amazon Linux 2 : procps-ng (ALAS-2019-1333)NessusAmazon Linux Local Security Checks
high
130145SUSE SLED15 / SLES15 Security Update : procps (SUSE-SU-2019:2730-1)NessusSuSE Local Security Checks
critical
129932NewStart CGSL CORE 5.04 / MAIN 5.04 : procps-ng Vulnerability (NS-SA-2019-0184)NessusNewStart CGSL Local Security Checks
high
128373CentOS 7 : procps-ng (CESA-2019:2189)NessusCentOS Local Security Checks
high
128253Scientific Linux Security Update : procps-ng on SL7.x x86_64 (20190806)NessusScientific Linux Local Security Checks
high
127694RHEL 7 : procps-ng (RHSA-2019:2189)NessusRed Hat Local Security Checks
high
122607openSUSE Security Update : procps (openSUSE-2019-291)NessusSuSE Local Security Checks
critical
122361SUSE SLED12 / SLES12 Security Update : procps (SUSE-SU-2019:0450-1)NessusSuSE Local Security Checks
critical
121983Photon OS 2.0: Procps PHSA-2018-2.0-0084NessusPhotonOS Local Security Checks
critical
121877Photon OS 1.0: Procps PHSA-2018-1.0-0175NessusPhotonOS Local Security Checks
critical
119211SUSE SLED12 / SLES12 Security Update : procps (SUSE-SU-2018:2451-2)NessusSuSE Local Security Checks
critical
118428EulerOS Virtualization 2.5.0 : procps-ng (EulerOS-SA-2018-1340)NessusHuawei Local Security Checks
critical
118414EulerOS Virtualization 2.5.1 : procps-ng (EulerOS-SA-2018-1326)NessusHuawei Local Security Checks
high
112035Photon OS 2.0: Openssl / Procps-ng / Perl PHSA-2018-2.0-0084 (deprecated)NessusPhotonOS Local Security Checks
critical
111650EulerOS 2.0 SP3 : procps-ng (EulerOS-SA-2018-1230)NessusHuawei Local Security Checks
high
111264SUSE SLES11 Security Update : procps (SUSE-SU-2018:2042-1)NessusSuSE Local Security Checks
critical
110862EulerOS 2.0 SP2 : procps-ng (EulerOS-SA-2018-1198)NessusHuawei Local Security Checks
critical
110830openSUSE Security Update : procps (openSUSE-2018-685)NessusSuSE Local Security Checks
critical
110804SUSE SLED12 / SLES12 Security Update : procps (SUSE-SU-2018:1836-1)NessusSuSE Local Security Checks
critical
110312Debian DLA-1390-1 : procps security updateNessusDebian Local Security Checks
critical
110255GLSA-201805-14 : procps: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
110094Ubuntu 14.04 LTS / 16.04 LTS / 17.10 / 18.04 LTS : procps-ng vulnerabilities (USN-3658-1)NessusUbuntu Local Security Checks
critical
109969Debian DSA-4208-1 : procps - security updateNessusDebian Local Security Checks
critical
109950Slackware 14.2 / current : procps-ng (SSA:2018-142-03)NessusSlackware Local Security Checks
critical