CVE-2023-4016: Buffer Overflow
procps-ng procps is vulnerable to a denial of service, caused by a heap based buffer overflow when running the “ps” utility. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4016?
CVE-2023-4016 has a severity rating that indicates it can cause a denial of service due to a heap-based buffer overflow.
How do I fix CVE-2023-4016?
To fix CVE-2023-4016, update the affected software to a version that addresses the buffer overflow vulnerability.
Who is affected by CVE-2023-4016?
CVE-2023-4016 affects the procps project, IBM Security Verify Governance, and Fedora 38 systems.
What type of attack does CVE-2023-4016 involve?
CVE-2023-4016 involves a local authenticated attacker exploiting a specially crafted request to trigger a denial of service.
What impact does CVE-2023-4016 have on systems?
CVE-2023-4016 can lead to a denial of service condition, rendering the affected systems temporarily inoperable.