Security Advisory

CVE-2018-1124

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-05-23 13:00:00
Last updated 2025-12-18 11:37:47
Assigner redhat
CVSS score 7.3
State PUBLISHED

Description

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.