CVE-2018-1124
published 2018-05-23CVE-2018-1124: procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege…
PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
1.83%
76.5th percentile
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | procps | < procps 2:3.3.15-1 (bookworm) | procps 2:3.3.15-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| paloalto | pan-os | — | — |
| procps-ng_project | procps-ng | < 3.3.15 | 3.3.15 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 1:3.3.9-1ubuntu2.3 | 1:3.3.9-1ubuntu2.3 |
| procps_project | procps | >= 0 < 2:3.3.10-4ubuntu2.4 | 2:3.3.10-4ubuntu2.4 |
| procps_project | procps | >= 0 < 2:3.3.12-3ubuntu1.1 | 2:3.3.12-3ubuntu1.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN
vendor_paloalto·2020-07-08·CVSS 9.8
CVE-2013-7459 [CRITICAL] PAN
PAN
The Palo Alto Networks Product Security Assurance team has evaluated and determined that these third-party or open source vulnerabilities do not have any security impact on PAN-OS or that the scenarios required for successful
CVEs: CVE-2013-7459, CVE-2018-1120, CVE-2018-1121, CVE-2018-1122, CVE-2018-1123, CVE-2018-1124, CVE-2018-16402, CVE-2020-11022, CVE-2020-11023, CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11899, CVE-2020-11900, CVE-2020-11901, CVE-2020-11902, CVE-2020-11903, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11908, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914
Affected products: PAN-OS
Ubuntu
procps-ng vulnerabilities
vendor_ubuntu·2018-06-05·CVSS 7.8
CVE-2018-1124 [HIGH] procps-ng vulnerabilities
Title: procps-ng vulnerabilities
Summary: Several security issues were fixed in procps-ng.
USN-3658-1 fixed a vulnerability in procps-ng. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libprocps incorrectly handled the file2strvec()
function. A local attacker could possibly use this to execute arbitrary
code. (CVE-2018-1124)
It was discovered that procps-ng incorrectly handled memory. A local
attacker could use this issue to cause a denial of service, or possibly
execute arbitrary code. (CVE-2018-1126)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
procps-ng vulnerabilities
vendor_ubuntu·2018-05-23·CVSS 7.3
CVE-2018-1122 [HIGH] procps-ng vulnerabilities
Title: procps-ng vulnerabilities
Summary: Several security issues were fixed in procps-ng.
It was discovered that the procps-ng top utility incorrectly read its
configuration file from the current working directory. A local attacker
could possibly use this issue to escalate privileges. (CVE-2018-1122)
It was discovered that the procps-ng ps tool incorrectly handled memory. A
local user could possibly use this issue to cause a denial of service.
(CVE-2018-1123)
It was discovered that libprocps incorrectly handled the file2strvec()
function. A local attacker could possibly use this to execute arbitrary
code. (CVE-2018-1124)
It was discovered that the procps-ng pgrep utility incorrectly handled
memory. A local attacker could possibly use this issue to cause de denial
of service. (CVE-201
Red Hat
procps: Integer overflows leading to heap overflow in file2strvec
vendor_redhat·2018-05-17·CVSS 7.8
CVE-2018-1124 [HIGH] CWE-190 procps: Integer overflows leading to heap overflow in file2strvec
procps: Integer overflows leading to heap overflow in file2strvec
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
Multiple integer overflows leading to heap corruption flaws were discovered in file2strvec(). These vulnerabilities can lead to privilege escalation for a local attacker who can create entries in procfs by starting processes, which will lead to crashes or arbitrary code execution in proc utilities run by other users (eg pgrep, pkill, pidof, w).
Package: procps (Red Hat Enterprise Linux 5) -
Red Hat
procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
vendor_redhat·2018-05-17·CVSS 7.8
CVE-2018-1126 [HIGH] CWE-190 procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
A flaw was found where procps-ng provides wrappers for standard C allocators that took `unsigned int` instead of `size_t` parameters. On platforms where these differ (such as x86_64), this could cause integer truncation, leading to undersized regions being returned to callers that could then be overflowed. The only known exploitable vector for this issue is CVE-2018-1124.
Package: procps (Red Hat Enterprise Linux 5) - Will not fix
Package: procps-ng (Red Hat Enterprise Linux 8) - Not affected
Package: procps-ng (Red H
Debian
CVE-2018-1124: procps - procps-ng before version 3.3.15 is vulnerable to multiple integer overflows lead...
vendor_debian·2018·CVSS 7.8
CVE-2018-1124 [HIGH] CVE-2018-1124: procps - procps-ng before version 3.3.15 is vulnerable to multiple integer overflows lead...
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
Scope: local
bookworm: resolved (fixed in 2:3.3.15-1)
bullseye: resolved (fixed in 2:3.3.15-1)
forky: resolved (fixed in 2:3.3.15-1)
sid: resolved (fixed in 2:3.3.15-1)
trixie: resolved (fixed in 2:3.3.15-1)
Debian
CVE-2018-1126: procps - procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in pr...
vendor_debian·2018·CVSS 7.8
CVE-2018-1126 [HIGH] CVE-2018-1126: procps - procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in pr...
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
Scope: local
bookworm: resolved (fixed in 2:3.3.15-1)
bullseye: resolved (fixed in 2:3.3.15-1)
forky: resolved (fixed in 2:3.3.15-1)
sid: resolved (fixed in 2:3.3.15-1)
trixie: resolved (fixed in 2:3.3.15-1)
GHSA
GHSA-3vhp-j7w2-qxhv: procps-ng before version 3
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2018-1126 [HIGH] CWE-190 GHSA-3vhp-j7w2-qxhv: procps-ng before version 3
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
GHSA
GHSA-6m7w-m36x-76pq: procps-ng before version 3
ghsa_unreviewed·2022-05-13
CVE-2018-1124 [HIGH] CWE-787 GHSA-6m7w-m36x-76pq: procps-ng before version 3
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
OSV
CVE-2018-1124: procps-ng before version 3
osv·2018-05-23·CVSS 7.8
CVE-2018-1124 [HIGH] CVE-2018-1124: procps-ng before version 3
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
OSV
CVE-2018-1126: procps-ng before version 3
osv·2018-05-23·CVSS 7.8
CVE-2018-1126 [HIGH] CVE-2018-1126: procps-ng before version 3
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
OSV
procps vulnerabilities
osv·2018-05-23·CVSS 7.0
CVE-2018-1122 [HIGH] procps vulnerabilities
procps vulnerabilities
It was discovered that the procps-ng top utility incorrectly read its
configuration file from the current working directory. A local attacker
could possibly use this issue to escalate privileges. (CVE-2018-1122)
It was discovered that the procps-ng ps tool incorrectly handled memory. A
local user could possibly use this issue to cause a denial of service.
(CVE-2018-1123)
It was discovered that libprocps incorrectly handled the file2strvec()
function. A local attacker could possibly use this to execute arbitrary
code. (CVE-2018-1124)
It was discovered that the procps-ng pgrep utility incorrectly handled
memory. A local attacker could possibly use this issue to cause de denial
of service. (CVE-2018-1125)
It was discovered that procps-ng incorrectly handled memory.
No detection rules found.
Bugzilla
CVE-2018-1124 procps-ng: procps-ng, procps: Integer overflows leading to heap overflow in file2strvec [fedora-all]
bugzilla·2018-05-18·CVSS 7.8
CVE-2018-1124 [HIGH] CVE-2018-1124 procps-ng: procps-ng, procps: Integer overflows leading to heap overflow in file2strvec [fedora-all]
CVE-2018-1124 procps-ng: procps-ng, procps: Integer overflows leading to heap overflow in file2strvec [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
bugzilla·2018-05-08·CVSS 7.8
CVE-2018-1126 [HIGH] CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
procps-ng provides wrappers for standard C allocators that took `unsigned int` instead of `size_t` parameters. On platforms where these differ (such as x86_64), this could cause integer truncation, leading to undersized regions being returned to callers that could then be overflowed.
This flaw is related to CVE-2018-1124. As stated in the patch provided by Qualys:
> this .. is one of the reasons the integer overflows in file2strvec() are exploitable at all.
Discussion:
This really needs a size limit in the kernel. It is not possible to pass more than 2 MiB of arguments to a process. (see "getconf ARG_MAX") If that limit were enforced by the /proc filesystem, then an
Bugzilla
CVE-2018-1124 procps-ng, procps: Integer overflows leading to heap overflow in file2strvec
bugzilla·2018-05-07·CVSS 7.8
CVE-2018-1124 [HIGH] CVE-2018-1124 procps-ng, procps: Integer overflows leading to heap overflow in file2strvec
CVE-2018-1124 procps-ng, procps: Integer overflows leading to heap overflow in file2strvec
Multiple integer overflows leading to heap corruption in file2strvec() lead to privilege escalation for a local attacker who can create entries in procfs by starting processes, which will lead to crashes or arbitrary code execution in proc utilities run by other users (eg pgrep, pkill, pidof, w)
Discussion:
See also bug 1575853:
> CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues.
CVE-2018-1126 was identified by Qualys as a precondition for the way they exploited CVE-2018-1124. Correcting that issue will prevent other flaws of this kind being introduced by future changes.
---
Generally, the /proc filesystem should not supply
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.htmlhttp://seclists.org/oss-sec/2018/q2/122http://www.securityfocus.com/bid/104214http://www.securitytracker.com/id/1041057https://access.redhat.com/errata/RHSA-2018:1700https://access.redhat.com/errata/RHSA-2018:1777https://access.redhat.com/errata/RHSA-2018:1820https://access.redhat.com/errata/RHSA-2018:2267https://access.redhat.com/errata/RHSA-2018:2268https://access.redhat.com/errata/RHSA-2019:1944https://access.redhat.com/errata/RHSA-2019:2401https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1124https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://kc.mcafee.com/corporate/index?page=content&id=SB10241https://lists.debian.org/debian-lts-announce/2018/05/msg00021.htmlhttps://security.gentoo.org/glsa/201805-14https://usn.ubuntu.com/3658-1/https://usn.ubuntu.com/3658-2/https://www.debian.org/security/2018/dsa-4208https://www.exploit-db.com/exploits/44806/https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txthttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.htmlhttp://seclists.org/oss-sec/2018/q2/122http://www.securityfocus.com/bid/104214http://www.securitytracker.com/id/1041057https://access.redhat.com/errata/RHSA-2018:1700https://access.redhat.com/errata/RHSA-2018:1777https://access.redhat.com/errata/RHSA-2018:1820https://access.redhat.com/errata/RHSA-2018:2267https://access.redhat.com/errata/RHSA-2018:2268https://access.redhat.com/errata/RHSA-2019:1944https://access.redhat.com/errata/RHSA-2019:2401https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1124https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://kc.mcafee.com/corporate/index?page=content&id=SB10241https://lists.debian.org/debian-lts-announce/2018/05/msg00021.htmlhttps://security.gentoo.org/glsa/201805-14https://usn.ubuntu.com/3658-1/https://usn.ubuntu.com/3658-2/https://www.debian.org/security/2018/dsa-4208https://www.exploit-db.com/exploits/44806/https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt
2018-05-23
Published