« Volver al listado

Apport Project

Apport Project Apport: vulnerabilidades y CVE

Apport Project Apport tiene 24 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE24
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-28658Media (5.5)0.20%—4 jun 2024
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
CVE-2022-28657Alta (7.8)0.23%—4 jun 2024
Apport does not disable python crash handler before entering chroot
CVE-2022-28656Media (5.5)0.20%—4 jun 2024
is_closing_session() allows users to consume RAM in the Apport process
CVE-2022-28655Alta (7.1)0.21%—4 jun 2024
is_closing_session() allows users to create arbitrary tcp dbus connections
CVE-2022-28654Media (5.5)0.25%—4 jun 2024
is_closing_session() allows users to fill up apport.log
CVE-2022-28652Media (5.5)0.20%—4 jun 2024
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
CVE-2019-15790Baja (3.3)0.52%—28 abr 2020
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in…
CVE-2020-8833Media (4.7)0.34%—22 abr 2020
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited…
CVE-2020-8831Media (5.5)0.65%—22 abr 2020
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the…
CVE-2019-11485Baja (3.3)0.26%—8 feb 2020
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
CVE-2019-11483Baja (3.3)0.40%—8 feb 2020
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
CVE-2019-11482Media (4.7)0.23%—8 feb 2020
Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.
CVE-2019-11481Alta (7.8)0.45%—8 feb 2020
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root,…
CVE-2019-7307Alta (7)0.33%—29 ago 2019
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which…
CVE-2018-6552Alta (7.8)0.39%—31 may 2018
Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion,…
CVE-2017-14180Alta (7.8)0.44%—2 feb 2018
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via…
CVE-2017-14179Alta (7.8)0.36%—2 feb 2018
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource…
CVE-2017-14177Alta (7.8)0.39%—2 feb 2018
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion…
CVE-2017-10708Alta (7.8)2.1%—18 jul 2017
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows…
CVE-2016-9951Media (6.5)6.7%—17 dic 2016
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch…
CVE-2016-9950Alta (7.8)6.5%—17 dic 2016
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in…
CVE-2016-9949Alta (7.8)18%—17 dic 2016
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary…
CVE-2015-1338Alta (7.2)0.91%—1 oct 2015
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
CVE-2015-1318Alta (7.2)4.2%—17 abr 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).