VendorsApport projectapportany version
Vulnerabilities

Apport project Apport any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2016-9949
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
Published 2016-12-17 · Modified
9.31 PoCEPSS 0.177
CVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.
Published 2016-12-17 · Modified
9.31 PoCEPSS 0.065
CVE-2017-10708
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file.
Published 2017-07-18 · Modified
7.8EPSS 0.021
CVE-2019-11481
Apport reads arbitrary files if ~/.config/apport/settings is a symlink
Published 2020-02-08 · Modified
7.8EPSS 0.005
CVE-2017-14180
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
Published 2018-02-02 · Modified
7.8EPSS 0.004
CVE-2017-14177
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.
Published 2018-02-02 · Modified
7.8EPSS 0.004
CVE-2017-14179
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.
Published 2018-02-02 · Modified
7.8EPSS 0.004
CVE-2022-28657
Apport does not disable python crash handler before entering chroot
Published 2024-06-04 · Modified
7.8EPSS 0.002
CVE-2015-1338
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
Published 2015-10-01 · Modified
7.21 PoCEPSS 0.009
CVE-2022-28655
is_closing_session() allows users to create arbitrary tcp dbus connections
Published 2024-06-04 · Modified
7.1EPSS 0.002
CVE-2019-11483
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
Published 2020-02-08 · Modified
7.0EPSS 0.004
CVE-2016-9951
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file. The fix is to only show the Relaunch button on Apport crash files generated by local systems. The Relaunch button will be hidden when crash files are opened directly in Apport-GTK.
Published 2016-12-17 · Modified
6.51 PoCEPSS 0.067
CVE-2020-8831
World writable root owned lock file created in user controllable location
Published 2020-04-22 · Modified
6.5EPSS 0.007
CVE-2020-8833
Apport race condition in crash report permissions
Published 2020-04-22 · Modified
5.6EPSS 0.003
CVE-2022-28654
is_closing_session() allows users to fill up apport.log
Published 2024-06-04 · Modified
5.5EPSS 0.003
CVE-2022-28658
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
Published 2024-06-04 · Modified
5.5EPSS 0.002
CVE-2022-28652
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
Published 2024-06-04 · Modified
5.5EPSS 0.002
CVE-2022-28656
is_closing_session() allows users to consume RAM in the Apport process
Published 2024-06-04 · Modified
5.5EPSS 0.002
CVE-2019-11482
Race condition between reading current working directory and writing a core dump
Published 2020-02-08 · Modified
4.7EPSS 0.002
CVE-2019-15790
Apport reads PID files with elevated privileges
Published 2020-04-27 · Modified
3.3EPSS 0.005
CVE-2019-11485
apport created lock file in wrong directory
Published 2020-02-08 · Modified
3.3EPSS 0.003