VDB
DEBIAN-CVE-2018-1124
DEBIAN-CVE-2018-1124
PUBLISHED
CVSS 7.800000190734863 HIGH
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
Risk Scores
CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | procps | 0, 0, 0 |
| Debian:11 | procps | 0, 0, 0 |
| Debian:13 | procps | 0, 0, 0 |
| Debian:14 | procps | 0, 0, 0 |
Timeline
- May 23, 2018 CVE Published
- Apr 28, 2026 CVE Updated