VYPR

Apport

by Apport Project

Source repositories

CVEs (29)

  • CVE-2022-28652MedJun 4, 2024
    risk 0.36cvss 5.5epss 0.00

    ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

  • CVE-2020-8833MedApr 22, 2020
    risk 0.36cvss 5.6epss 0.00

    Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited between the os.open and os.chown calls when the Apport cron…

  • CVE-2019-11482MedFeb 8, 2020
    risk 0.27cvss 4.2epss 0.00

    Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.

  • CVE-2019-11481LowFeb 8, 2020
    risk 0.25cvss 3.8epss 0.00

    Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.

  • CVE-2019-11485LowFeb 8, 2020
    risk 0.21cvss 3.3epss 0.00

    Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.

  • CVE-2019-15790LowApr 28, 2020
    risk 0.18cvss 2.8epss 0.01

    Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read…

  • CVE-2015-1338Oct 1, 2015
    risk 0.03cvss epss 0.01

    kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

  • CVE-2015-1318Apr 17, 2015
    risk 0.03cvss epss 0.04

    The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

  • CVE-2009-1295Apr 30, 2009
    risk 0.00cvss epss 0.00

    Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.

Page 2 of 2