7.8

CVE-2017-14177

Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apport Project ≫ Apport Version <= 2.20.7
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.04
Canonical ≫ Ubuntu Linux Version 17.10
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://bazaar.launchpad.net/~apport-hackers/apport/trunk/revision/3171
Third Party Advisory
Issue Tracking
https://launchpad.net/bugs/1726372
Third Party Advisory
Issue Tracking
https://people.canonical.com/~ubuntu-security/cve/?cve=CVE-2017-14177
Third Party Advisory
https://usn.ubuntu.com/usn/usn-3480-1
Third Party Advisory