Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4016

Опубликовано: 02 авг. 2023
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.

A heap-based buffer overflow vulnerability was found in the procps project when handling untrusted input with the -C option. This issue may allow a user with "ps" utility access to write unfiltered data into the process heap, triggering an out-of-bounds write, consuming memory and causing a crash, resulting in a denial of service.

Отчет

The affected package is procps, the command line utility known as “ps” used to understand the current state of any running processes. On 32 bit systems it is possible to use specific parameters with the -C option to trigger more memory allocation than should be allowed. As this outcome is restricted to local authenticated users, a malicious user in this situation has far more powerful tools at their disposal to bring down the server, for example by simply turning it off. For this reason Red Hat Product Security rates the impact as Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6procpsOut of support scope
Red Hat Enterprise Linux 7procps-ngOut of support scope
Red Hat OpenShift Container Platform 4procps-ngNot affected
Red Hat Enterprise Linux 8procps-ngFixedRHSA-2023:718714.11.2023
Red Hat Enterprise Linux 9procps-ngFixedRHSA-2023:670507.11.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119->CWE-787

EPSS

Процентиль: 1%
0.0001
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
около 2 лет назад

Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.

CVSS3: 2.5
nvd
около 2 лет назад

Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.

CVSS3: 2.5
debian
около 2 лет назад

Under some circumstances, this weakness allows a user who has access t ...

suse-cvrf
6 месяцев назад

Security update for procps

suse-cvrf
6 месяцев назад

Security update for procps

EPSS

Процентиль: 1%
0.0001
Низкий

3.3 Low

CVSS3