Low severity3.8NVD Advisory· Published Feb 8, 2020· Updated Jun 17, 2026
CVE-2019-11481
CVE-2019-11481
Description
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:a:apport_project:apport:-:*:*:*:*:*:*:*
- Range: 2.14.1
Patches
Vulnerability mechanics
References
3- usn.ubuntu.com/usn/usn-4171-1nvdThird Party Advisory
- usn.ubuntu.com/usn/usn-4171-2nvdThird Party Advisory
- packetstormsecurity.com/files/172858/Ubuntu-Apport-Whoopsie-DoS-Integer-Overflow.htmlnvd
News mentions
0No linked articles in our index yet.