OESA-2023-1514
Dashboard / Vulnerabilities / OESA-2023-1514
Summary: procps-ng security update
Details: The procps package contains a set of system utilities that provide system information. Procps includes ps, free, skill, pkill, pgrep, snice, tload, top, uptime, vmstat, pidof, pmap, slabtop, w, watch and pwdx. Security Fix(es): Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.(CVE-2023-4016)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1514, https://nvd.nist.gov/vuln/detail/CVE-2023-4016
Affected packages
Package
Name: procps-ng
Purl: pkg:rpm/openEuler/procps-ng&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
