VYPR

Apport

by Ubuntu

CVEs (35)

  • CVE-2021-25683HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.00

    It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.

  • CVE-2021-25682HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.00

    It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

  • CVE-2016-9949HigDec 17, 2016
    risk 0.55cvss 7.8epss 0.18

    An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.

  • CVE-2022-28657HigJun 4, 2024
    risk 0.51cvss 7.8epss 0.00

    Apport does not disable python crash handler before entering chroot

  • CVE-2022-1242HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Apport can be tricked into connecting to arbitrary sockets as the root user

  • CVE-2021-3899HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

  • CVE-2018-6552HigMay 31, 2018
    risk 0.51cvss 7.8epss 0.00

    Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The…

  • CVE-2015-1325HigAug 25, 2017
    risk 0.49cvss 7.0epss 0.01

    Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write…

  • CVE-2015-1341HigApr 22, 2019
    risk 0.48cvss 7.4epss 0.00

    Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

  • CVE-2021-32555HigJun 12, 2021
    risk 0.47cvss 7.3epss 0.00

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.

  • CVE-2021-32554HigJun 12, 2021
    risk 0.47cvss 7.3epss 0.00

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.

  • CVE-2020-15702HigAug 6, 2020
    risk 0.46cvss 7.0epss 0.01

    TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to…

  • CVE-2019-11483HigFeb 8, 2020
    risk 0.46cvss 7.0epss 0.00

    Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

  • CVE-2019-7307HigAug 29, 2019
    risk 0.46cvss 7.0epss 0.00

    Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allows a local attacker to replace this file with a symlink to…

  • CVE-2015-1324HigAug 25, 2017
    risk 0.44cvss 7.8epss 0.00

    Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files…

  • CVE-2021-3710MedOct 1, 2021
    risk 0.42cvss 6.5epss 0.00

    An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2; 2.20.9 versions prior to 2.20.9-0ubuntu7.26;…

  • CVE-2021-3709MedOct 1, 2021
    risk 0.42cvss 6.5epss 0.00

    Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file. This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2;…

  • CVE-2020-8831MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply continue execution using…

  • CVE-2019-11484MedFeb 8, 2020
    risk 0.41cvss 6.3epss 0.00

    Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.

  • CVE-2022-28658MedJun 4, 2024
    risk 0.36cvss 5.5epss 0.00

    Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Page 1 of 2