Buffer overflow in procps - CVE-2018-1126

 

Buffer overflow in procps - CVE-2018-1126

Published: May 23, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU12992
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1126
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to improper bounds checking. A remote attacker can send a specially crafted request, trigger memory corruption and execute arbitrary code with elevated privileges.


Affected software

procps
Traffix SDC
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
Opensuse
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
BIG-IQ Centralized Management
BIG-IP DDHD
BIG-IP
BIG-IP SSLO
BIG-IP AFM
BIG-IP FPS
BIG-IP ASM
BIG-IP Analytics
BIG-IP GTM
BIG-IP LTM
BIG-IP PEM
BIG-IP APM
BIG-IP DNS
BIG-IP AAM
BIG-IP Link Controller
BIG-IP Advanced WAF
openSUSE Leap
procps-ng
Dynamic System Analysis (DSA) Preboot
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2018-1126

Update to version 3.3.15.

Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
procps-ng - addressed in versions 3.3.10-16.fc27, 3.3.12-2.fc28
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins