7.8

CVE-2017-14180

Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apport Project ≫ Apport Version >= 2.13 <= 2.20.7
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.04
Canonical ≫ Ubuntu Linux Version 17.10
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.355
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://bazaar.launchpad.net/~apport-hackers/apport/trunk/revision/3171
Third Party Advisory
Issue Tracking
https://launchpad.net/bugs/1726372
Third Party Advisory
Issue Tracking
https://usn.ubuntu.com/usn/usn-3480-1
Third Party Advisory
https://people.canonical.com/~ubuntu-security/cve/?cve=CVE-2017-14180
Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jun/9