CVE-2018-1123 is a denial-of-service vulnerability affecting procps-ng versions prior to 3.3.15, specifically impacting the 'ps' utility through a mmap buffer overflow. This flaw, present in various Canonical and Debian Linux distributions, can lead to a system crash due to an inbuilt guard page, limiting the impact to a temporary denial of service. With a CVSS v3 score of 7.5 (HIGH), it is easily exploitable over the network with low attack complexity and no user interaction, resulting in high availability impact. While not listed in CISA's KEV catalog and lacking Metasploit or Nuclei exploits, an ExploitDB entry (EDB-44806) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.15CPE matchmatch criteria | cpe:2.3:a:procps-ng_project:procps-ng:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.