Apport Project
apport_project
24 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Jun 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Apport does not disable python crash handler before entering chroot |
2Apport Project Canonical2Apport Ubuntu LinuxMar 19, 2025 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 is_closing_session() allows users to consume RAM in the Apport process |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Jun 4, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 is_closing_session() allows users to create arbitrary tcp dbus connections |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 is_closing_session() allows users to fill up apport.log |
2Apport Project Canonical2Apport Ubuntu LinuxMar 13, 2025 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Apr 28, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport....Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Apr 22, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited betwee...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Apr 22, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the d...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 8, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling. |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Feb 8, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user. |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 8, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories. |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 8, 2020 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, w...Show more |
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allow...Show more |
Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possi...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resour...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhau...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion...Show more |
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows r...Show more |
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button...Show more |