Integer overflow in procps - CVE-2018-1124

 

Integer overflow in procps - CVE-2018-1124

Published: May 22, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU12977
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1124
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to integer overflow in libprocps's file2strvec() function. A local attacker can execute a vulnerable utility (pgrep, pidof, pkill, and w are vulnerable by default; other utilities are vulnerable if executed with non-default options) and gain elevated privileges.

Affected software

procps
Traffix SDC
Debian Linux
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
Opensuse
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
BIG-IQ Centralized Management
McAfee Web Gateway
BIG-IP
BIG-IP DDHD
BIG-IP SSLO
BIG-IP LTM
BIG-IP AFM
BIG-IP APM
BIG-IP ASM
BIG-IP FPS
BIG-IP GTM
BIG-IP PEM
BIG-IP Analytics
BIG-IP AAM
BIG-IP DNS
BIG-IP Link Controller
BIG-IP Advanced WAF
openSUSE Leap
procps-ng
Dynamic System Analysis (DSA) Preboot
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2018-1124

Update to version 3.3.15.

Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
procps-ng - addressed in versions 3.3.10-16.fc27, 3.3.12-2.fc28
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins