UBUNTU-CVE-2018-1124
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1124
UBUNTU-CVE-2018-1124
Summary:
Details: procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
References: https://ubuntu.com/security/CVE-2018-1124, https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt, https://ubuntu.com/security/notices/USN-3658-1, https://ubuntu.com/security/notices/USN-3658-2, https://www.cve.org/CVERecord?id=CVE-2018-1124
Affected packages
Package
Name: procps
Purl: pkg:deb/ubuntu/procps@1:3.3.9-1ubuntu2.3?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
