Oval Definition:oval:org.opensuse.security:def:63861
Revision Date:2020-12-01Version:1
Title:Security update for procps (Important)
Description:



This update for procps fixes the following security issues:

- CVE-2018-1122: Prevent local privilege escalation in top. If a user ran top with HOME unset in an attacker-controlled directory, the attacker could have achieved privilege escalation by exploiting one of several vulnerabilities in the config_file() function (bsc#1092100). - CVE-2018-1123: Prevent denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maped a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service) (bsc#1092100). - CVE-2018-1124: Prevent multiple integer overflows leading to a heap corruption in file2strvec function. This allowed a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users (bsc#1092100). - CVE-2018-1125: Prevent stack buffer overflow in pgrep. This vulnerability was mitigated by FORTIFY limiting the impact to a crash (bsc#1092100). - CVE-2018-1126: Ensure correct integer size in proc/alloc.* to prevent truncation/integer overflow issues (bsc#1092100).

(These issues were previously released for SUSE Linux Enterprise 12 SP3 and SP4.)

Also the following non-security issue was fixed:

- Fix CPU summary showing old data. (bsc#1121753)
Family:unixClass:patch
Status:Reference(s):1043983
1048072
1055265
1056286
1056782
1058115
1058754
1058755
1058757
1062452
1069607
1069632
1071995
1073002
1078782
1082007
1082008
1082009
1082010
1082011
1082014
1082058
1087369
1087433
1087434
1087436
1087437
1087440
1087441
1092100
1111733
1112530
1112532
1115016
1121753
1130611
1130617
1130620
1130622
1130623
1130627
1130721
1138172
1138173
1140844
1144333
1152990
1152992
1152994
1152995
1153722
1154212
1154366
1158442
1162396
1164804
1165629
1166751
1171517
1171988
1172275
1172428
1172963
1173455
1173798
1173954
1174205
1174457
1174689
1174699
1174757
1174784
1174978
1175112
1175127
1175213
1175228
1175515
1175518
1175691
1175749
1176069
CVE-2012-6708
CVE-2015-9096
CVE-2015-9251
CVE-2016-2339
CVE-2016-7798
CVE-2017-0898
CVE-2017-0899
CVE-2017-0900
CVE-2017-0901
CVE-2017-0902
CVE-2017-0903
CVE-2017-10784
CVE-2017-14033
CVE-2017-14064
CVE-2017-17405
CVE-2017-17742
CVE-2017-17790
CVE-2017-9228
CVE-2017-9229
CVE-2018-1000073
CVE-2018-1000074
CVE-2018-1000075
CVE-2018-1000076
CVE-2018-1000077
CVE-2018-1000078
CVE-2018-1000079
CVE-2018-1122
CVE-2018-1123
CVE-2018-1124
CVE-2018-1125
CVE-2018-1126
CVE-2018-16395
CVE-2018-16396
CVE-2018-19052
CVE-2018-6914
CVE-2018-8777
CVE-2018-8778
CVE-2018-8779
CVE-2018-8780
CVE-2019-11039
CVE-2019-11040
CVE-2019-15845
CVE-2019-16201
CVE-2019-16254
CVE-2019-16255
CVE-2019-1787
CVE-2019-1788
CVE-2019-1789
CVE-2019-2933
CVE-2019-2945
CVE-2019-2962
CVE-2019-2964
CVE-2019-2973
CVE-2019-2978
CVE-2019-2981
CVE-2019-2983
CVE-2019-2989
CVE-2019-2992
CVE-2019-2999
CVE-2019-8320
CVE-2019-8321
CVE-2019-8322
CVE-2019-8323
CVE-2019-8324
CVE-2019-8325
CVE-2020-0556
CVE-2020-10135
CVE-2020-10663
CVE-2020-14314
CVE-2020-14331
CVE-2020-14356
CVE-2020-14386
CVE-2020-15049
CVE-2020-15917
CVE-2020-16166
CVE-2020-1749
CVE-2020-24394
CVE-2020-8130
openSUSE-SU-2019:1778-1
openSUSE-SU-2019:2347-1
openSUSE-SU-2020:0395-1
openSUSE-SU-2020:0872-1
openSUSE-SU-2020:1139-1
SUSE-SU-2019:0450-1
SUSE-SU-2019:0897-1
SUSE-SU-2020:0051-1
SUSE-SU-2020:1570-1
SUSE-SU-2020:2623-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • apache2-mod_php7-7.2.5-lp151.6.6 is installed
  • OR php7-7.2.5-lp151.6.6 is installed
  • OR php7-bcmath-7.2.5-lp151.6.6 is installed
  • OR php7-bz2-7.2.5-lp151.6.6 is installed
  • OR php7-calendar-7.2.5-lp151.6.6 is installed
  • OR php7-ctype-7.2.5-lp151.6.6 is installed
  • OR php7-curl-7.2.5-lp151.6.6 is installed
  • OR php7-dba-7.2.5-lp151.6.6 is installed
  • OR php7-devel-7.2.5-lp151.6.6 is installed
  • OR php7-dom-7.2.5-lp151.6.6 is installed
  • OR php7-embed-7.2.5-lp151.6.6 is installed
  • OR php7-enchant-7.2.5-lp151.6.6 is installed
  • OR php7-exif-7.2.5-lp151.6.6 is installed
  • OR php7-fastcgi-7.2.5-lp151.6.6 is installed
  • OR php7-fileinfo-7.2.5-lp151.6.6 is installed
  • OR php7-firebird-7.2.5-lp151.6.6 is installed
  • OR php7-fpm-7.2.5-lp151.6.6 is installed
  • OR php7-ftp-7.2.5-lp151.6.6 is installed
  • OR php7-gd-7.2.5-lp151.6.6 is installed
  • OR php7-gettext-7.2.5-lp151.6.6 is installed
  • OR php7-gmp-7.2.5-lp151.6.6 is installed
  • OR php7-iconv-7.2.5-lp151.6.6 is installed
  • OR php7-intl-7.2.5-lp151.6.6 is installed
  • OR php7-json-7.2.5-lp151.6.6 is installed
  • OR php7-ldap-7.2.5-lp151.6.6 is installed
  • OR php7-mbstring-7.2.5-lp151.6.6 is installed
  • OR php7-mysql-7.2.5-lp151.6.6 is installed
  • OR php7-odbc-7.2.5-lp151.6.6 is installed
  • OR php7-opcache-7.2.5-lp151.6.6 is installed
  • OR php7-openssl-7.2.5-lp151.6.6 is installed
  • OR php7-pcntl-7.2.5-lp151.6.6 is installed
  • OR php7-pdo-7.2.5-lp151.6.6 is installed
  • OR php7-pear-7.2.5-lp151.6.6 is installed
  • OR php7-pear-Archive_Tar-7.2.5-lp151.6.6 is installed
  • OR php7-pgsql-7.2.5-lp151.6.6 is installed
  • OR php7-phar-7.2.5-lp151.6.6 is installed
  • OR php7-posix-7.2.5-lp151.6.6 is installed
  • OR php7-readline-7.2.5-lp151.6.6 is installed
  • OR php7-shmop-7.2.5-lp151.6.6 is installed
  • OR php7-snmp-7.2.5-lp151.6.6 is installed
  • OR php7-soap-7.2.5-lp151.6.6 is installed
  • OR php7-sockets-7.2.5-lp151.6.6 is installed
  • OR php7-sodium-7.2.5-lp151.6.6 is installed
  • OR php7-sqlite-7.2.5-lp151.6.6 is installed
  • OR php7-sysvmsg-7.2.5-lp151.6.6 is installed
  • OR php7-sysvsem-7.2.5-lp151.6.6 is installed
  • OR php7-sysvshm-7.2.5-lp151.6.6 is installed
  • OR php7-testresults-7.2.5-lp151.6.6 is installed
  • OR php7-tidy-7.2.5-lp151.6.6 is installed
  • OR php7-tokenizer-7.2.5-lp151.6.6 is installed
  • OR php7-wddx-7.2.5-lp151.6.6 is installed
  • OR php7-xmlreader-7.2.5-lp151.6.6 is installed
  • OR php7-xmlrpc-7.2.5-lp151.6.6 is installed
  • OR php7-xmlwriter-7.2.5-lp151.6.6 is installed
  • OR php7-xsl-7.2.5-lp151.6.6 is installed
  • OR php7-zip-7.2.5-lp151.6.6 is installed
  • OR php7-zlib-7.2.5-lp151.6.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • claws-mail-3.17.6-lp152.3.3 is installed
  • OR claws-mail-devel-3.17.6-lp152.3.3 is installed
  • OR claws-mail-lang-3.17.6-lp152.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libprocps3-3.3.9-11.18 is installed
  • OR procps-3.3.9-11.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND squid-3.5.21-26.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • kernel-default-4.12.14-95.60 is installed
  • OR kernel-default-base-4.12.14-95.60 is installed
  • OR kernel-default-devel-4.12.14-95.60 is installed
  • OR kernel-default-man-4.12.14-95.60 is installed
  • OR kernel-devel-4.12.14-95.60 is installed
  • OR kernel-macros-4.12.14-95.60 is installed
  • OR kernel-source-4.12.14-95.60 is installed
  • OR kernel-syms-4.12.14-95.60 is installed
  • BACK