Описание
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
A flaw was found where procps-ng provides wrappers for standard C allocators that took unsigned int instead of size_t parameters. On platforms where these differ (such as x86_64), this could cause integer truncation, leading to undersized regions being returned to callers that could then be overflowed. The only known exploitable vector for this issue is CVE-2018-1124.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | procps | Will not fix | ||
| Red Hat Enterprise Linux 8 | procps-ng | Not affected | ||
| Red Hat Enterprise Linux 9 | procps-ng | Not affected | ||
| Red Hat Enterprise Linux 6 | procps | Fixed | RHSA-2018:1777 | 31.05.2018 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | procps | Fixed | RHSA-2018:2268 | 26.07.2018 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | procps | Fixed | RHSA-2018:2268 | 26.07.2018 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | procps | Fixed | RHSA-2018:2267 | 26.07.2018 |
| Red Hat Enterprise Linux 7 | procps-ng | Fixed | RHSA-2018:1700 | 23.05.2018 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | procps-ng | Fixed | RHSA-2019:1944 | 30.07.2019 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased | Fixed | RHSA-2018:1820 | 11.06.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
procps-ng before version 3.3.15 is vulnerable to an incorrect integer ...
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
Уязвимость функции file2strvec набора утилит командной строки procps-ng, позволяющая нарушителю повысить привилегии и выполнить произвольный код
EPSS
4.8 Medium
CVSS3