Red Hat Bugzilla – Bug 1575466
CVE-2018-1122 procps-ng, procps: Local privilege escalation in top
Last modified: 2018-09-11 20:20:13 EDT
If the HOME environment variable is unset or empty, top will read its configuration file from the current working directory without any security check. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could acieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.
Acknowledgments: Name: Qualys Research Labs
Public via: http://seclists.org/oss-sec/2018/q2/122
External References: https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt
Created procps-ng tracking bugs for this issue: Affects: fedora-all [bug 1579639]