Buffer overflow in procps - CVE-2018-1126
Published: May 23, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU12992
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1126
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to improper bounds checking. A remote attacker can send a specially crafted request, trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
procps
Traffix SDC
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
Opensuse
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
BIG-IQ Centralized Management
BIG-IP DDHD
BIG-IP
BIG-IP SSLO
BIG-IP AFM
BIG-IP FPS
BIG-IP ASM
BIG-IP Analytics
BIG-IP GTM
BIG-IP LTM
BIG-IP PEM
BIG-IP APM
BIG-IP DNS
BIG-IP AAM
BIG-IP Link Controller
BIG-IP Advanced WAF
openSUSE Leap
procps-ng
Dynamic System Analysis (DSA) Preboot
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Traffix SDC
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
Opensuse
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
BIG-IQ Centralized Management
BIG-IP DDHD
BIG-IP
BIG-IP SSLO
BIG-IP AFM
BIG-IP FPS
BIG-IP ASM
BIG-IP Analytics
BIG-IP GTM
BIG-IP LTM
BIG-IP PEM
BIG-IP APM
BIG-IP DNS
BIG-IP AAM
BIG-IP Link Controller
BIG-IP Advanced WAF
openSUSE Leap
procps-ng
Dynamic System Analysis (DSA) Preboot
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2018-1126
Update to version 3.3.15.
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
procps-ng - addressed in versions 3.3.10-16.fc27, 3.3.12-2.fc28
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
procps-ng - addressed in versions 3.3.10-16.fc27, 3.3.12-2.fc28
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in procps
- Slackware Linux update for procps-ng
- Debian update for procps
- Red Hat update for procps
- Red Hat update for procps
- Red Hat update for procps
- Red Hat update for procps
- Arch Linux update for procps-ng
- OpenSUSE Linux update for procps
- Red Hat update for procps
- Red Hat update for procps
- OpenSUSE Linux update for procps
- Red Hat update for procps-ng
- OpenSUSE Linux update for procps
- OpenSUSE Linux update for procps
- Multiple vulnerabilities in procps-ng component in F5 BIG-IP products
- Multiple vulnerabilities in F5 BIG-IQ Centralized Management
- Multiple vulnerabilities in procps-ng component in F5 Traffix SDC
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 27 update for procps-ng
- Fedora 28 update for procps-ng