Vulnerability Description
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Procps Project | Procps | >= 3.3.0, <= 4.0.3 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://gitlab.com/procps-ng/procpsProduct
- https://lists.fedoraproject.org/archives/list/[email protected]MitigationThird Party Advisory
- https://gitlab.com/procps-ng/procpsProduct
- https://lists.fedoraproject.org/archives/list/[email protected]MitigationThird Party Advisory
FAQ
What is CVE-2023-4016?
CVE-2023-4016 is a vulnerability with a CVSS score of 2.5 (LOW). Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.
How severe is CVE-2023-4016?
CVE-2023-4016 has been rated LOW with a CVSS base score of 2.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4016?
Check the references section above for vendor advisories and patch information. Affected products include: Procps Project Procps, Fedoraproject Fedora.