« Volver al listado

Canonical

Canonical Apport: vulnerabilidades y CVE

Canonical Apport tiene 18 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE18
Últimos 12 meses2
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77113Media (6.7)0.20%—20 ago 2026
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker…
CVE-2025-5467Baja (1.9)0.18%—10 dic 2025
It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended…
CVE-2025-5054Media (4.7)0.74%—30 may 2025
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function…
CVE-2020-11936Baja (3.1)0.34%—31 ene 2025
gdbus setgid privilege escalation
CVE-2022-28653Alta (7.5)0.40%—31 ene 2025
Users can consume unlimited disk space in /var/crash
CVE-2022-1242Alta (7.8)0.23%—3 jun 2024
Apport can be tricked into connecting to arbitrary sockets as the root user
CVE-2021-3899Alta (7.8)0.38%—3 jun 2024
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
CVE-2023-1326Alta (7.8)0.87%—13 abr 2023
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as…
CVE-2021-3710Media (5.5)0.46%—1 oct 2021
—
CVE-2021-3709Media (5.5)0.46%—1 oct 2021
—
CVE-2021-32557Alta (7.1)0.39%—12 jun 2021
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
CVE-2021-32556Baja (3.3)0.33%—12 jun 2021
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
CVE-2021-25684Alta (7.8)0.57%—11 jun 2021
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
CVE-2021-25683Alta (7.8)0.43%—11 jun 2021
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
CVE-2021-25682Alta (7.8)0.45%—11 jun 2021
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
CVE-2020-15702Alta (7)0.50%—6 ago 2020
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with…
CVE-2020-15701Media (5.5)0.43%—6 ago 2020
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an…
CVE-2015-1341Alta (7.8)0.43%—22 abr 2019
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

📰 Noticias relacionadas

Otros productos de Canonical