procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2018-05-23T13:00:00
Updated: 2019-10-26T23:06:10
Reserved: 2017-12-04T00:00:00
Link: CVE-2018-1124
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-05-23T13:29:00.263
Modified: 2020-09-09T14:58:59.730
Link: CVE-2018-1124
JSON object: View
Redhat Information
No data.