Apport
Apport Project · 26 CVEs
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
Jun 4, 2024
Apport does not disable python crash handler before entering chroot
Jun 4, 2024
is_closing_session() allows users to consume RAM in the Apport process
Jun 4, 2024
is_closing_session() allows users to create arbitrary tcp dbus connections
Jun 4, 2024
is_closing_session() allows users to fill up apport.log
Jun 4, 2024
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
Jun 4, 2024
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an a…
Jun 3, 2024
Apport reads PID files with elevated privileges
Apr 27, 2020
Apport race condition in crash report permissions
Apr 22, 2020
World writable root owned lock file created in user controllable location
Apr 22, 2020
apport created lock file in wrong directory
Feb 8, 2020
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker…
Feb 8, 2020
Race condition between reading current working directory and writing a core dump
Feb 8, 2020
Apport reads arbitrary files if ~/.config/apport/settings is a symlink
Feb 8, 2020
Apport contains a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml
Aug 29, 2019
Apport treats the container PID as the global PID when /proc/<global_pid>/ is missing
May 31, 2018
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to cr…
Feb 2, 2018
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create cer…
Feb 2, 2018
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain f…
Feb 2, 2018
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then…
Jul 18, 2017
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `Respaw…
Dec 17, 2016
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and…
Dec 17, 2016
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates…
Dec 17, 2016
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly g…
Oct 1, 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a cra…
Apr 17, 2015
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-28658 | Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing | MEDIUM | 0.20% | Jun 4, 2024 |
| CVE-2022-28657 | Apport does not disable python crash handler before entering chroot | HIGH | 0.23% | Jun 4, 2024 |
| CVE-2022-28656 | is_closing_session() allows users to consume RAM in the Apport process | MEDIUM | 0.20% | Jun 4, 2024 |
| CVE-2022-28655 | is_closing_session() allows users to create arbitrary tcp dbus connections | HIGH | 0.21% | Jun 4, 2024 |
| CVE-2022-28654 | is_closing_session() allows users to fill up apport.log | MEDIUM | 0.25% | Jun 4, 2024 |
| CVE-2022-28652 | ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack | MEDIUM | 0.20% | Jun 4, 2024 |
| CVE-2021-3899 | There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as roo… | HIGH | 0.38% | Jun 3, 2024 |
| CVE-2019-15790 | Apport reads PID files with elevated privileges | LOW | 0.52% | Apr 27, 2020 |
| CVE-2020-8833 | Apport race condition in crash report permissions | MEDIUM | 0.34% | Apr 22, 2020 |
| CVE-2020-8831 | World writable root owned lock file created in user controllable location | MEDIUM | 0.65% | Apr 22, 2020 |
| CVE-2019-11485 | apport created lock file in wrong directory | LOW | 0.26% | Feb 8, 2020 |
| CVE-2019-11483 | Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privil… | HIGH | 0.40% | Feb 8, 2020 |
| CVE-2019-11482 | Race condition between reading current working directory and writing a core dump | MEDIUM | 0.23% | Feb 8, 2020 |
| CVE-2019-11481 | Apport reads arbitrary files if ~/.config/apport/settings is a symlink | HIGH | 0.45% | Feb 8, 2020 |
| CVE-2019-7307 | Apport contains a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml | HIGH | 0.33% | Aug 29, 2019 |
| CVE-2018-6552 | Apport treats the container PID as the global PID when /proc/<global_pid>/ is missing | HIGH | 0.39% | May 31, 2018 |
| CVE-2017-14180 | Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an atta… | HIGH | 0.44% | Feb 2, 2018 |
| CVE-2017-14179 | Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker cou… | HIGH | 0.36% | Feb 2, 2018 |
| CVE-2017-14177 | Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could lev… | HIGH | 0.39% | Feb 2, 2018 |
| CVE-2017-10708 | An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific h… | HIGH | 2.10% | Jul 18, 2017 |
| CVE-2016-9951 | An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This… | MEDIUM | 6.67% | Dec 17, 2016 |
| CVE-2016-9950 | An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields ar… | HIGH | 6.55% | Dec 17, 2016 |
| CVE-2016-9949 | An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins wi… | HIGH | 17.73% | Dec 17, 2016 |
| CVE-2015-1338 | kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2)… | HIGH | 0.91% | Oct 1, 2015 |
| CVE-2015-1318 | The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a n… | HIGH | 4.19% | Apr 17, 2015 |
Showing 1 to 25 of 26 CVEs