PublicDateAtUSN: 2018-05-17 17:00:00 UTC Candidate: CVE-2018-1122 CRD: 2018-05-17 17:00:00 UTC PublicDate: 2018-05-23 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1122 https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt https://ubuntu.com/security/notices/USN-3658-1 https://ubuntu.com/security/notices/USN-3658-3 Description: procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function. Ubuntu-Description: Notes: mdeslaur> [PATCH 097/117] top: Do not default to the cwd in configs_read(). leosilva> for precise/esm code request a POC test, and a huge backport. Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=899170 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.0 HIGH] Patches_procps: upstream: https://gitlab.com/procps-ng/procps/commit/b45c4803dd176f4e3f9d3d47421ddec9bbbe66cd upstream_procps: released (3.3.15) precise/esm_procps: released (1:3.2.8-11ubuntu6.6) trusty_procps: released (1:3.3.9-1ubuntu2.3) trusty/esm_procps: released (1:3.3.9-1ubuntu2.3) xenial_procps: released (2:3.3.10-4ubuntu2.4) esm-infra/xenial_procps: released (2:3.3.10-4ubuntu2.4) artful_procps: released (2:3.3.12-1ubuntu2.1) bionic_procps: released (2:3.3.12-3ubuntu1.1) devel_procps: released (2:3.3.15-2ubuntu1)