CVE-2018-1126
published 2018-05-23CVE-2018-1126: procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
1.99%
78.4th percentile
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | procps | < procps 2:3.3.15-1 (bookworm) | procps 2:3.3.15-1 (bookworm) |
| procps-ng_project | procps-ng | < 3.3.15 | 3.3.15 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 2:3.3.15-1 | 2:3.3.15-1 |
| procps_project | procps | >= 0 < 1:3.3.9-1ubuntu2.3 | 1:3.3.9-1ubuntu2.3 |
| procps_project | procps | >= 0 < 2:3.3.10-4ubuntu2.4 | 2:3.3.10-4ubuntu2.4 |
| procps_project | procps | >= 0 < 2:3.3.12-3ubuntu1.1 | 2:3.3.12-3ubuntu1.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| schneider-electric | struxureware_data_center_expert | < 7.6.0 | 7.6.0 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
procps-ng vulnerabilities
vendor_ubuntu·2018-06-05·CVSS 7.8
CVE-2018-1124 [HIGH] procps-ng vulnerabilities
Title: procps-ng vulnerabilities
Summary: Several security issues were fixed in procps-ng.
USN-3658-1 fixed a vulnerability in procps-ng. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libprocps incorrectly handled the file2strvec()
function. A local attacker could possibly use this to execute arbitrary
code. (CVE-2018-1124)
It was discovered that procps-ng incorrectly handled memory. A local
attacker could use this issue to cause a denial of service, or possibly
execute arbitrary code. (CVE-2018-1126)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
procps-ng vulnerabilities
vendor_ubuntu·2018-05-23·CVSS 7.3
CVE-2018-1122 [HIGH] procps-ng vulnerabilities
Title: procps-ng vulnerabilities
Summary: Several security issues were fixed in procps-ng.
It was discovered that the procps-ng top utility incorrectly read its
configuration file from the current working directory. A local attacker
could possibly use this issue to escalate privileges. (CVE-2018-1122)
It was discovered that the procps-ng ps tool incorrectly handled memory. A
local user could possibly use this issue to cause a denial of service.
(CVE-2018-1123)
It was discovered that libprocps incorrectly handled the file2strvec()
function. A local attacker could possibly use this to execute arbitrary
code. (CVE-2018-1124)
It was discovered that the procps-ng pgrep utility incorrectly handled
memory. A local attacker could possibly use this issue to cause de denial
of service. (CVE-201
Red Hat
procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
vendor_redhat·2018-05-17·CVSS 7.8
CVE-2018-1126 [HIGH] CWE-190 procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
A flaw was found where procps-ng provides wrappers for standard C allocators that took `unsigned int` instead of `size_t` parameters. On platforms where these differ (such as x86_64), this could cause integer truncation, leading to undersized regions being returned to callers that could then be overflowed. The only known exploitable vector for this issue is CVE-2018-1124.
Package: procps (Red Hat Enterprise Linux 5) - Will not fix
Package: procps-ng (Red Hat Enterprise Linux 8) - Not affected
Package: procps-ng (Red H
Debian
CVE-2018-1126: procps - procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in pr...
vendor_debian·2018·CVSS 7.8
CVE-2018-1126 [HIGH] CVE-2018-1126: procps - procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in pr...
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
Scope: local
bookworm: resolved (fixed in 2:3.3.15-1)
bullseye: resolved (fixed in 2:3.3.15-1)
forky: resolved (fixed in 2:3.3.15-1)
sid: resolved (fixed in 2:3.3.15-1)
trixie: resolved (fixed in 2:3.3.15-1)
GHSA
GHSA-3vhp-j7w2-qxhv: procps-ng before version 3
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2018-1126 [HIGH] CWE-190 GHSA-3vhp-j7w2-qxhv: procps-ng before version 3
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
OSV
CVE-2018-1126: procps-ng before version 3
osv·2018-05-23·CVSS 7.8
CVE-2018-1126 [HIGH] CVE-2018-1126: procps-ng before version 3
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
OSV
procps vulnerabilities
osv·2018-05-23·CVSS 7.0
CVE-2018-1122 [HIGH] procps vulnerabilities
procps vulnerabilities
It was discovered that the procps-ng top utility incorrectly read its
configuration file from the current working directory. A local attacker
could possibly use this issue to escalate privileges. (CVE-2018-1122)
It was discovered that the procps-ng ps tool incorrectly handled memory. A
local user could possibly use this issue to cause a denial of service.
(CVE-2018-1123)
It was discovered that libprocps incorrectly handled the file2strvec()
function. A local attacker could possibly use this to execute arbitrary
code. (CVE-2018-1124)
It was discovered that the procps-ng pgrep utility incorrectly handled
memory. A local attacker could possibly use this issue to cause de denial
of service. (CVE-2018-1125)
It was discovered that procps-ng incorrectly handled memory.
No detection rules found.
Tenable
Critical Vulnerability Fixes Available For Juniper Devices
blogs_tenable·2019-01-10
Critical Vulnerability Fixes Available For Juniper Devices
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Critical Vulnerability Fixes Available For Juniper Devices
blogs_tenable·2019-01-10·CVSS 9.8
[CRITICAL] Critical Vulnerability Fixes Available For Juniper Devices
Blog / Cyber Exposure Alerts
Subscribe
# Critical Vulnerability Fixes Available For Juniper Devices
Ryan Seguin
January 10, 2019
2 Min Read
Juniper has addressed multiple critical vulnerabilities in Junos, Junos Space, and JATP devices. Administrators are advised to update to the latest OS version on any affected Juniper device.
## Background
Juniper has released a number of security advisories this week which include critical vulnerabilities across many of its devices. The Juniper Advanced Threat Prevention Appliance (JATP) update removes hardcoded admin credentials, while the Junos updates include patches for remote code execution (RCE) and denial of service (DoS) vulnerabilities. Junos Space network management devices are also vulnerable to a memory allocation vulnerability which
Bugzilla
CVE-2018-16375 openjpeg: Heap-based buffer overflow in pnmtoimage function in bin/jpwl/convert.c
bugzilla·2018-09-06·CVSS 8.8
CVE-2018-16375 [HIGH] CVE-2018-16375 openjpeg: Heap-based buffer overflow in pnmtoimage function in bin/jpwl/convert.c
CVE-2018-16375 openjpeg: Heap-based buffer overflow in pnmtoimage function in bin/jpwl/convert.c
An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.
Upstream bug:
https://github.com/uclouvain/openjpeg/issues/1126
Discussion:
Upstream issue: https://github.com/uclouvain/openjpeg/issues/861
Patch: https://github.com/uclouvain/openjpeg/commit/c22cbd8bdf8ff2ae372f94391a4be2d322b36b41
Analysis:
Heap-buffer overflow while converting image from PNM format. Specially-crafted values in the header, could cause integer overflow. This leads to a small buffer being allocated. Later when file contents are read into this buffer it leads to heap-overflow. Arbi
Bugzilla
CVE-2018-14355 mutt: IMAP header caching path traversal vulnerability
bugzilla·2018-07-17·CVSS 5.3
CVE-2018-14355 [MEDIUM] CVE-2018-14355 mutt: IMAP header caching path traversal vulnerability
CVE-2018-14355 mutt: IMAP header caching path traversal vulnerability
A flaw was found in mutt before 1.10.1. There is a path traversal flaw in IMAP header caching.
References:
http://www.mutt.org/news.html
https://gitlab.com/muttmua/mutt/blob/master/ChangeLog
Discussion:
Created attachment 1459537
upstream patch
---
Created mutt tracking bugs for this issue:
Affects: fedora-all [bug 1602082]
---
Upstream Patch:
https://gitlab.com/muttmua/mutt/commit/31eef6c766f47df8281942d19f76e35f475c781d
---
Setting rhel-6 as wontfix and closing tracker. Our policy specifies that we may not fix moderate flaws for rhel-6.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1126 https://access.redhat.com/errata/RHSA-2020:1126
---
This bug
Bugzilla
CVE-2018-1126 procps-ng: procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues [fedora-all]
bugzilla·2018-05-18·CVSS 4.8
CVE-2018-1126 [MEDIUM] CVE-2018-1126 procps-ng: procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues [fedora-all]
CVE-2018-1126 procps-ng: procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg com
Bugzilla
CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
bugzilla·2018-05-08·CVSS 7.8
CVE-2018-1126 [HIGH] CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues
procps-ng provides wrappers for standard C allocators that took `unsigned int` instead of `size_t` parameters. On platforms where these differ (such as x86_64), this could cause integer truncation, leading to undersized regions being returned to callers that could then be overflowed.
This flaw is related to CVE-2018-1124. As stated in the patch provided by Qualys:
> this .. is one of the reasons the integer overflows in file2strvec() are exploitable at all.
Discussion:
This really needs a size limit in the kernel. It is not possible to pass more than 2 MiB of arguments to a process. (see "getconf ARG_MAX") If that limit were enforced by the /proc filesystem, then an
Bugzilla
CVE-2018-1124 procps-ng, procps: Integer overflows leading to heap overflow in file2strvec
bugzilla·2018-05-07·CVSS 7.8
CVE-2018-1124 [HIGH] CVE-2018-1124 procps-ng, procps: Integer overflows leading to heap overflow in file2strvec
CVE-2018-1124 procps-ng, procps: Integer overflows leading to heap overflow in file2strvec
Multiple integer overflows leading to heap corruption in file2strvec() lead to privilege escalation for a local attacker who can create entries in procfs by starting processes, which will lead to crashes or arbitrary code execution in proc utilities run by other users (eg pgrep, pkill, pidof, w)
Discussion:
See also bug 1575853:
> CVE-2018-1126 procps-ng, procps: incorrect integer size in proc/alloc.* leading to truncation / integer overflow issues.
CVE-2018-1126 was identified by Qualys as a precondition for the way they exploited CVE-2018-1124. Correcting that issue will prevent other flaws of this kind being introduced by future changes.
---
Generally, the /proc filesystem should not supply
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.htmlhttp://seclists.org/oss-sec/2018/q2/122http://www.securityfocus.com/bid/104214http://www.securitytracker.com/id/1041057https://access.redhat.com/errata/RHSA-2018:1700https://access.redhat.com/errata/RHSA-2018:1777https://access.redhat.com/errata/RHSA-2018:1820https://access.redhat.com/errata/RHSA-2018:2267https://access.redhat.com/errata/RHSA-2018:2268https://access.redhat.com/errata/RHSA-2019:1944https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1126https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/05/msg00021.htmlhttps://usn.ubuntu.com/3658-1/https://usn.ubuntu.com/3658-2/https://www.debian.org/security/2018/dsa-4208https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txthttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.htmlhttp://seclists.org/oss-sec/2018/q2/122http://www.securityfocus.com/bid/104214http://www.securitytracker.com/id/1041057https://access.redhat.com/errata/RHSA-2018:1700https://access.redhat.com/errata/RHSA-2018:1777https://access.redhat.com/errata/RHSA-2018:1820https://access.redhat.com/errata/RHSA-2018:2267https://access.redhat.com/errata/RHSA-2018:2268https://access.redhat.com/errata/RHSA-2019:1944https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1126https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/05/msg00021.htmlhttps://usn.ubuntu.com/3658-1/https://usn.ubuntu.com/3658-2/https://www.debian.org/security/2018/dsa-4208https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt
2018-05-23
Published