Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Leap 42.3: 2018:1848-1 Moderate: Procps Local Escalation

opensuse
Calendar Grey June 29, 2018
Dist Opensuse Esm H88
This patch addresses several vulnerabilities such as local authorization escalation and service interruption within procps.
An update that fixes 5 vulnerabilities is now available.

Description

This update for procps fixes the following security issues:

- CVE-2018-1122: Prevent local privilege escalation in top. If a user ran

top with HOME unset in an attacker-controlled directory, the attacker

could have achieved privilege escalation by exploiting one of several

vulnerabilities in the config_file() function (bsc#1092100).

- CVE-2018-1123: Prevent denial of service in ps via mmap buffer overflow.

Inbuilt protection in ps maped a guard page at the end of the overflowed

buffer, ensuring that the impact of this flaw is limited to a crash

(temporary denial of service) (bsc#1092100).

- CVE-2018-1124: Prevent multiple integer overflows leading to a heap

corruption in file2strvec function. This allowed a privilege escalation

for a local attacker who can create entries in procfs by starting

processes, which could result in crashes or arbitrary code execution in

proc utilities run by

other users (bsc#1092100).

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-685=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

libprocps3-3.3.9-20.1

libprocps3-debuginfo-3.3.9-20.1

procps-3.3.9-20.1

procps-debuginfo-3.3.9-20.1

procps-debugsource-3.3.9-20.1

procps-devel-3.3.9-20.1

References

https://www.suse.com/security/cve/CVE-2018-1122.html

https://www.suse.com/security/cve/CVE-2018-1123.html

https://www.suse.com/security/cve/CVE-2018-1124.html

https://www.suse.com/security/cve/CVE-2018-1125.html

https://www.suse.com/security/cve/CVE-2018-1126.html

https://bugzilla.suse.com/show_bug.cgi?id=1092100

--

Announcement ID: openSUSE-SU-2018:1848-1
Rating: moderate
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here