PT-2018-1901 · Procps Ng+3 · Procps-Ng+3
Published
2018-05-17
·
Updated
2025-12-17
·
CVE-2018-1125
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
procps-ng versions prior to 3.3.15
Description
The issue is related to a stack buffer overflow error in the pgrep function of the procps-ng set of console applications for monitoring and terminating system processes. This error can be exploited by a remote attacker using specially crafted processes, potentially leading to a denial of service. The impact is limited to a crash when pgrep is compiled with FORTIFY, as seen on Red Hat Enterprise Linux and Fedora.
Recommendations
For versions prior to 3.3.15, update to version 3.3.15 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pgrep function until a patch is available.
Exploit
Fix
Stack Overflow
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Procps-Ng