Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1122
HistoryMay 18, 2018 - 5:20 a.m.

CVE-2018-1122

2018-05-1805:20:23
redhat.com
access.redhat.com
15

0.0004 Low

EPSS

Percentile

10.1%

If the HOME environment variable is unset or empty, top will read its configuration file from the current working directory without any security check. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.