CVE-2018-1124 is a critical vulnerability affecting procps-ng versions prior to 3.3.15, impacting various Linux distributions including Canonical, Debian, and Red Hat. This flaw involves multiple integer overflows in the file2strvec function, leading to heap corruption. A local attacker can leverage this to achieve privilege escalation, potentially causing system crashes or arbitrary code execution within proc utilities run by other users. While not actively exploited in the wild and not on the KEV catalog, public exploit code exists on ExploitDB, and its high CVSS score of 7.8 (High) and FAUCET Risk Score of 89/100 underscore its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.15CPE matchmatch criteria | cpe:2.3:a:procps-ng_project:procps-ng:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.