PT-2018-1901 · Procps Ng+3 · Procps-Ng+3

Published

2018-05-17

·

Updated

2025-12-17

·

CVE-2018-1125

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions procps-ng versions prior to 3.3.15
Description The issue is related to a stack buffer overflow error in the pgrep function of the procps-ng set of console applications for monitoring and terminating system processes. This error can be exploited by a remote attacker using specially crafted processes, potentially leading to a denial of service. The impact is limited to a crash when pgrep is compiled with FORTIFY, as seen on Red Hat Enterprise Linux and Fedora.
Recommendations For versions prior to 3.3.15, update to version 3.3.15 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pgrep function until a patch is available.

Exploit

Fix

Stack Overflow

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1749
BDU:2018-01505
CVE-2018-1125
DLA-1390-1
DSA-4208-1
OPENSUSE-SU-2018_1848-1
OPENSUSE-SU-2019:2376-1
OPENSUSE-SU-2019:2379-1
OPENSUSE-SU-2019_0291-1
OPENSUSE-SU-2019_2376-1
OPENSUSE-SU-2019_2379-1
OPENSUSE-SU-2024:11195-1
OPENSUSE-SU-2024:12565-1
SUSE-SU-2018:1836-1
SUSE-SU-2018:2042-1
SUSE-SU-2018:2451-2
SUSE-SU-2019:0450-1
SUSE-SU-2019:0450-2
SUSE-SU-2019:2730-1
USN-3658-1
USN-3658-3

Affected Products

Alt Linux
Suse
Ubuntu
Procps-Ng