Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2018-1125
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
栈缓冲区溢出
Source: NVD (National Vulnerability Database)
Vulnerability Title
procps-ng pgrep 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
procps/procps-ng是一款使用在Linux平台中的用于提供proc文件系统进程信息的实用程序。pgrep是其中的一个用于查找进程ID的命令行工具。 procps-ng 3.3.15之前版本中的pgrep存在缓冲区错误漏洞,该漏洞源于程序没有正确检查边界。远程攻击者可借助特制请求利用该漏洞在系统上执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
[UNKNOWN]procps-ng, procps procps-ng 3.3.15 -
II. Public POCs for CVE-2018-1125
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2018-1125
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2018-1125

No comments yet


Leave a comment