Apport

Apport Project · 26 CVEs

CVE-2022-28658
MEDIUM

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Jun 4, 2024

CVE-2022-28657
HIGH

Apport does not disable python crash handler before entering chroot

Jun 4, 2024

CVE-2022-28656
MEDIUM

is_closing_session() allows users to consume RAM in the Apport process

Jun 4, 2024

CVE-2022-28655
HIGH

is_closing_session() allows users to create arbitrary tcp dbus connections

Jun 4, 2024

CVE-2022-28654
MEDIUM

is_closing_session() allows users to fill up apport.log

Jun 4, 2024

CVE-2022-28652
MEDIUM

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

Jun 4, 2024

CVE-2021-3899
HIGH

There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an a…

Jun 3, 2024

CVE-2019-15790
LOW

Apport reads PID files with elevated privileges

Apr 27, 2020

CVE-2020-8833
MEDIUM

Apport race condition in crash report permissions

Apr 22, 2020

CVE-2020-8831
MEDIUM

World writable root owned lock file created in user controllable location

Apr 22, 2020

CVE-2019-11485
LOW

apport created lock file in wrong directory

Feb 8, 2020

CVE-2019-11483
HIGH

Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker…

Feb 8, 2020

CVE-2019-11482
MEDIUM

Race condition between reading current working directory and writing a core dump

Feb 8, 2020

CVE-2019-11481
HIGH

Apport reads arbitrary files if ~/.config/apport/settings is a symlink

Feb 8, 2020

CVE-2019-7307
HIGH

Apport contains a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml

Aug 29, 2019

CVE-2018-6552
HIGH

Apport treats the container PID as the global PID when /proc/<global_pid>/ is missing

May 31, 2018

CVE-2017-14180
HIGH

Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to cr…

Feb 2, 2018

CVE-2017-14179
HIGH

Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create cer…

Feb 2, 2018

CVE-2017-14177
HIGH

Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain f…

Feb 2, 2018

CVE-2017-10708
HIGH

An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then…

Jul 18, 2017

CVE-2016-9951
MEDIUM

An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `Respaw…

Dec 17, 2016

CVE-2016-9950
HIGH

An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and…

Dec 17, 2016

CVE-2016-9949
HIGH

An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates…

Dec 17, 2016

CVE-2015-1338
HIGH

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly g…

Oct 1, 2015

CVE-2015-1318
HIGH

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a cra…

Apr 17, 2015

Showing 1 to 25 of 26 CVEs