CVE-2018-1124

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.

References

http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html

http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html

http://seclists.org/oss-sec/2018/q2/122

http://www.securityfocus.com/bid/104214

http://www.securitytracker.com/id/1041057

https://access.redhat.com/errata/RHSA-2018:1700

https://access.redhat.com/errata/RHSA-2018:1777

https://access.redhat.com/errata/RHSA-2018:1820

https://access.redhat.com/errata/RHSA-2018:2267

https://access.redhat.com/errata/RHSA-2018:2268

https://access.redhat.com/errata/RHSA-2019:1944

https://access.redhat.com/errata/RHSA-2019:2401

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1124

https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0

https://kc.mcafee.com/corporate/index?page=content&id=SB10241

https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html

https://security.gentoo.org/glsa/201805-14

https://usn.ubuntu.com/3658-1/

https://usn.ubuntu.com/3658-2/

https://www.debian.org/security/2018/dsa-4208

https://www.exploit-db.com/exploits/44806/

https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt

Details

Source: MITRE

Published: 2018-05-23

Updated: 2020-09-09

Type: CWE-787

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (42 total)

IDNameProductFamilySeverity
130334openSUSE Security Update : procps (openSUSE-2019-2379)NessusSuSE Local Security Checks
critical
130333openSUSE Security Update : procps (openSUSE-2019-2376)NessusSuSE Local Security Checks
critical
130145SUSE SLED15 / SLES15 Security Update : procps (SUSE-SU-2019:2730-1)NessusSuSE Local Security Checks
critical
127718RHEL 7 : procps-ng (RHSA-2019:2401)NessusRed Hat Local Security Checks
high
127631RHEL 7 : procps-ng (RHSA-2019:1944)NessusRed Hat Local Security Checks
critical
127432NewStart CGSL MAIN 4.05 : procps Multiple Vulnerabilities (NS-SA-2019-0155)NessusNewStart CGSL Local Security Checks
critical
127394NewStart CGSL MAIN 4.05 : procps Multiple Vulnerabilities (NS-SA-2019-0135)NessusNewStart CGSL Local Security Checks
critical
127175NewStart CGSL CORE 5.04 / MAIN 5.04 : procps-ng Multiple Vulnerabilities (NS-SA-2019-0019)NessusNewStart CGSL Local Security Checks
critical
122607openSUSE Security Update : procps (openSUSE-2019-291)NessusSuSE Local Security Checks
critical
122361SUSE SLED12 / SLES12 Security Update : procps (SUSE-SU-2019:0450-1)NessusSuSE Local Security Checks
critical
121983Photon OS 2.0: Procps PHSA-2018-2.0-0084NessusPhotonOS Local Security Checks
critical
121877Photon OS 1.0: Procps PHSA-2018-1.0-0175NessusPhotonOS Local Security Checks
critical
121068Juniper Junos Space 18.4.x < 18.4R1 Multiple Vulnerabilities (JSA10917)NessusJunos Local Security Checks
high
120743Fedora 28 : procps-ng (2018-bba8fed5ab)NessusFedora Local Security Checks
critical
119211SUSE SLED12 / SLES12 Security Update : procps (SUSE-SU-2018:2451-2)NessusSuSE Local Security Checks
critical
118428EulerOS Virtualization 2.5.0 : procps-ng (EulerOS-SA-2018-1340)NessusHuawei Local Security Checks
critical
117583EulerOS Virtualization 2.5.1 : procps-ng (EulerOS-SA-2018-1274)NessusHuawei Local Security Checks
critical
112035Photon OS 2.0: Openssl / Procps-ng / Perl PHSA-2018-2.0-0084 (deprecated)NessusPhotonOS Local Security Checks
critical
111366RHEL 6 : procps (RHSA-2018:2268)NessusRed Hat Local Security Checks
critical
111365RHEL 6 : procps (RHSA-2018:2267)NessusRed Hat Local Security Checks
critical
111264SUSE SLES11 Security Update : procps (SUSE-SU-2018:2042-1)NessusSuSE Local Security Checks
critical
110863EulerOS 2.0 SP3 : procps-ng (EulerOS-SA-2018-1199)NessusHuawei Local Security Checks
critical
110862EulerOS 2.0 SP2 : procps-ng (EulerOS-SA-2018-1198)NessusHuawei Local Security Checks
critical
110830openSUSE Security Update : procps (openSUSE-2018-685)NessusSuSE Local Security Checks
critical
110804SUSE SLED12 / SLES12 Security Update : procps (SUSE-SU-2018:1836-1)NessusSuSE Local Security Checks
critical
110467RHEL 7 : Virtualization (RHSA-2018:1820)NessusRed Hat Local Security Checks
critical
110448Amazon Linux 2 : procps-ng (ALAS-2018-1031)NessusAmazon Linux Local Security Checks
critical
110312Debian DLA-1390-1 : procps security updateNessusDebian Local Security Checks
critical
110306OracleVM 3.3 / 3.4 : procps (OVMSA-2018-0226)NessusOracleVM Local Security Checks
critical
110296CentOS 6 : procps (CESA-2018:1777)NessusCentOS Local Security Checks
critical
110282Scientific Linux Security Update : procps on SL6.x i386/x86_64 (20180531)NessusScientific Linux Local Security Checks
critical
110279RHEL 6 : procps (RHSA-2018:1777)NessusRed Hat Local Security Checks
critical
110276Oracle Linux 6 : procps (ELSA-2018-1777)NessusOracle Linux Local Security Checks
critical
110255GLSA-201805-14 : procps: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
110204CentOS 7 : procps-ng (CESA-2018:1700)NessusCentOS Local Security Checks
critical
110103Fedora 27 : procps-ng (2018-de5de06754)NessusFedora Local Security Checks
critical
110094Ubuntu 14.04 LTS / 16.04 LTS / 17.10 / 18.04 LTS : procps-ng vulnerabilities (USN-3658-1)NessusUbuntu Local Security Checks
critical
110088Scientific Linux Security Update : procps-ng on SL7.x x86_64 (20180523)NessusScientific Linux Local Security Checks
critical
110082RHEL 7 : procps-ng (RHSA-2018:1700)NessusRed Hat Local Security Checks
critical
110070Oracle Linux 7 : procps-ng (ELSA-2018-1700)NessusOracle Linux Local Security Checks
critical
109969Debian DSA-4208-1 : procps - security updateNessusDebian Local Security Checks
critical
109950Slackware 14.2 / current : procps-ng (SSA:2018-142-03)NessusSlackware Local Security Checks
critical