PublicDateAtUSN: 2018-05-17 17:00:00 UTC Candidate: CVE-2018-1123 CRD: 2018-05-17 17:00:00 UTC PublicDate: 2018-05-23 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1123 https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt https://ubuntu.com/security/notices/USN-3658-1 https://ubuntu.com/security/notices/USN-3658-3 Description: procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service). Ubuntu-Description: Notes: mdeslaur> [PATCH 054/117] ps/output.c: Fix outbuf overflows in pr_args() etc. Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=899170 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_procps: upstream: https://gitlab.com/procps-ng/procps/commit/136e3724952827bbae8887a42d9d2b6f658a48ab upstream_procps: released (3.3.15) precise/esm_procps: released (1:3.2.8-11ubuntu6.6) trusty_procps: released (1:3.3.9-1ubuntu2.3) trusty/esm_procps: released (1:3.3.9-1ubuntu2.3) xenial_procps: released (2:3.3.10-4ubuntu2.4) esm-infra/xenial_procps: released (2:3.3.10-4ubuntu2.4) artful_procps: released (2:3.3.12-1ubuntu2.1) bionic_procps: released (2:3.3.12-3ubuntu1.1) devel_procps: released (2:3.3.15-2ubuntu1)