Canonical
Canonical Apport: vulnerabilidades y CVE
Canonical Apport tiene 18 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77113 | Media (6.7) | 0.20% | — | 20 ago 2026 | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker… |
| CVE-2025-5467 | Baja (1.9) | 0.18% | — | 10 dic 2025 | It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended… |
| CVE-2025-5054 | Media (4.7) | 0.74% | — | 30 may 2025 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function… |
| CVE-2020-11936 | Baja (3.1) | 0.34% | — | 31 ene 2025 | gdbus setgid privilege escalation |
| CVE-2022-28653 | Alta (7.5) | 0.40% | — | 31 ene 2025 | Users can consume unlimited disk space in /var/crash |
| CVE-2022-1242 | Alta (7.8) | 0.23% | — | 3 jun 2024 | Apport can be tricked into connecting to arbitrary sockets as the root user |
| CVE-2021-3899 | Alta (7.8) | 0.38% | — | 3 jun 2024 | There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. |
| CVE-2023-1326 | Alta (7.8) | 0.87% | — | 13 abr 2023 | A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as… |
| CVE-2021-3710 | Media (5.5) | 0.46% | — | 1 oct 2021 | — |
| CVE-2021-3709 | Media (5.5) | 0.46% | — | 1 oct 2021 | — |
| CVE-2021-32557 | Alta (7.1) | 0.39% | — | 12 jun 2021 | It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks. |
| CVE-2021-32556 | Baja (3.3) | 0.33% | — | 12 jun 2021 | It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call. |
| CVE-2021-25684 | Alta (7.8) | 0.57% | — | 11 jun 2021 | It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO. |
| CVE-2021-25683 | Alta (7.8) | 0.43% | — | 11 jun 2021 | It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel. |
| CVE-2021-25682 | Alta (7.8) | 0.45% | — | 11 jun 2021 | It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. |
| CVE-2020-15702 | Alta (7) | 0.50% | — | 6 ago 2020 | TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with… |
| CVE-2020-15701 | Media (5.5) | 0.43% | — | 6 ago 2020 | An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an… |
| CVE-2015-1341 | Alta (7.8) | 0.43% | — | 22 abr 2019 | Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path. |