Back

HIGH

procps: Local privilege escalation in top

Published May 23, 2018

Description

procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (18)

Change history (6)
  1. MITRE
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H to CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
    • CVSS score changed from 6.7 to 7.3
  2. REDHAT
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H to CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
    • CVSS score changed from 7.3 to 6.7
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 23, 2018
Updated Aug 5, 2024
Reserved Dec 4, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 17, 2018