peter bassill · operator
$ cve CVE-2018-1124 JSON

CVE-2018-1124 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.9% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-122
On CISA KEVno
Public exploityes
Published2018-05-23
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
opensuseleap
procps-ng projectprocps-ng
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
schneider-electricstruxureware data center expert

Public exploits

SourceTitleDate
exploit-dbProcps-ng - Multiple Vulnerabilities2018-05-30

References

→ the Explorer  ·  watch your stack  ·  NVD