Canonical

Apport

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 22:32:51
  • Zuletzt bearbeitet 20.08.2026 23:16:28

Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report fi...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 10.12.2025 18:00:35
  • Zuletzt bearbeitet 17.12.2025 17:12:03

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 30.05.2025 17:37:01
  • Zuletzt bearbeitet 03.11.2025 20:19:15

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the ...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 31.01.2025 02:15:28
  • Zuletzt bearbeitet 26.08.2025 17:49:17

gdbus setgid privilege escalation

  • EPSS 0.39%
  • Veröffentlicht 31.01.2025 01:15:08
  • Zuletzt bearbeitet 26.08.2025 17:49:27

Users can consume unlimited disk space in /var/crash

  • EPSS 0.23%
  • Veröffentlicht 03.06.2024 19:15:09
  • Zuletzt bearbeitet 22.08.2025 15:48:00

Apport can be tricked into connecting to arbitrary sockets as the root user

  • EPSS 0.38%
  • Veröffentlicht 03.06.2024 19:15:08
  • Zuletzt bearbeitet 26.08.2025 17:21:04

There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

  • EPSS 0.87%
  • Veröffentlicht 13.04.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 07:38:55

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal siz...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 01.10.2021 03:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:12

An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2; 2.20.9 versions pr...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 01.10.2021 03:15:06
  • Zuletzt bearbeitet 21.11.2024 06:22:12

Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file. This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior t...