Errata overview
Errata ID 137
Date 2018-07-04
Source package procps
Fixed in version 2:3.3.12-3+deb9u1
Description
This update addresses the following issues:
* Local privilege escalation in top (CVE-2018-1122)
* Denial of service in ps via mmap buffer overflow (CVE-2018-1123)
* Integer overflows leading to heap overflow in file2strvec (CVE-2018-1124)
* Stack buffer overflow in pgrep (CVE-2018-1125)
* Incorrect integer size in proc/alloc.* leading to truncation / integer
  overflow issues (CVE-2018-1126)
Additional notes
CVE ID CVE-2018-1122
CVE-2018-1123
CVE-2018-1124
CVE-2018-1125
CVE-2018-1126
UCS Bug number #47296