Vulnerabilities > CVE-2022-28652 - XML Entity Expansion vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
apport-project
canonical
CWE-776

Summary

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

Vulnerable Configurations

Part Description Count
Application
Apport_Project
113
OS
Canonical
4