Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
2020-02-08T05:15:12.527
2024-11-21T04:21:10.220
Modified
CVSSv3.1: 3.8 (LOW)
AV:L/AC:L/Au:N/C:C/I:P/A:P
3.9
8.5
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Operating System | canonical | ubuntu_linux | 19.04 | Yes |
| Operating System | canonical | ubuntu_linux | 19.10 | Yes |
| Application | apport_project | apport | - | Yes |