Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6477-1

Ubuntu Security Notice 6477-1 - It was discovered that the procps-ng ps tool incorrectly handled memory. An attacker could possibly use this issue to cause procps-ng to crash, resulting in a denial of service.

Packet Storm
#vulnerability#ubuntu#dos

==========================================================================
Ubuntu Security Notice USN-6477-1
November 14, 2023

procps vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 23.10
  • Ubuntu 23.04
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 LTS (Available with Ubuntu Pro)
  • Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

procps-ng could be made to crash if it received specially crafted input.

Software Description:

  • procps: /proc file system utilities

Details:

It was discovered that the procps-ng ps tool incorrectly handled memory.
An attacker could possibly use this issue to cause procps-ng to crash,
resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
procps 2:4.0.3-1ubuntu1.23.10.1

Ubuntu 23.04:
procps 2:4.0.3-1ubuntu1.23.04.1

Ubuntu 22.04 LTS:
procps 2:3.3.17-6ubuntu2.1

Ubuntu 20.04 LTS:
procps 2:3.3.16-1ubuntu2.4

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
procps 2:3.3.12-3ubuntu1.2+esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
procps 2:3.3.10-4ubuntu2.5+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6477-1
CVE-2023-4016

Package Information:
https://launchpad.net/ubuntu/+source/procps/2:4.0.3-1ubuntu1.23.10.1
https://launchpad.net/ubuntu/+source/procps/2:4.0.3-1ubuntu1.23.04.1
https://launchpad.net/ubuntu/+source/procps/2:3.3.17-6ubuntu2.1
https://launchpad.net/ubuntu/+source/procps/2:3.3.16-1ubuntu2.4

Related news

CVE-2023-48660: DSA-2023-443: Dell PowerMaxOS 5978, Dell Unisphere 360, Dell Unisphere for PowerMax, Dell Unisphere for PowerMax Virtual Appliance, Dell Solutions Enabler Virtual Appliance, and Dell PowerMax EEM Secu

Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system.

CVE-2023-45085: Releases - HyperCloud Docs

An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process.  In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed during this time window. This issue impacts HyperCloud versions from 2.0.0 to before 2.0.3.

Red Hat Security Advisory 2023-7187-01

Red Hat Security Advisory 2023-7187-01 - An update for procps-ng is now available for Red Hat Enterprise Linux 8. Issues addressed include a buffer overflow vulnerability.

CVE-2023-4016: procps-ng / procps · GitLab

Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.

Packet Storm: Latest News

Zeek 6.0.9