PublicDateAtUSN: 2018-05-17 17:00:00 UTC Candidate: CVE-2018-1125 CRD: 2018-05-17 17:00:00 UTC PublicDate: 2018-05-23 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1125 https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt https://ubuntu.com/security/notices/USN-3658-1 https://ubuntu.com/security/notices/USN-3658-3 Description: procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash. Ubuntu-Description: Notes: mdeslaur> [PATCH 008/117] pgrep: Prevent a potential stack-based buffer mdeslaur> overflow. Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=899170 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_procps: upstream: https://gitlab.com/procps-ng/procps/commit/b51ca2a1f8ca779f7632ade6a0a259ed882fa584 upstream_procps: released (3.3.15) precise/esm_procps: released (1:3.2.8-11ubuntu6.6) trusty_procps: released (1:3.3.9-1ubuntu2.3) trusty/esm_procps: released (1:3.3.9-1ubuntu2.3) xenial_procps: released (2:3.3.10-4ubuntu2.4) esm-infra/xenial_procps: released (2:3.3.10-4ubuntu2.4) artful_procps: released (2:3.3.12-1ubuntu2.1) bionic_procps: released (2:3.3.12-3ubuntu1.1) devel_procps: released (2:3.3.15-2ubuntu1)