Vulnerabilities > Canonical > Apport

DATE CVE VULNERABILITY TITLE RISK
2023-04-13 CVE-2023-1326 Improper Privilege Management vulnerability in Canonical Apport
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604.
local
low complexity
canonical CWE-269
7.8
2021-10-01 CVE-2021-3709 Path Traversal vulnerability in Canonical Apport
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file.
local
low complexity
canonical CWE-22
5.5
2021-10-01 CVE-2021-3710 Path Traversal vulnerability in Canonical Apport
An information disclosure via path traversal was discovered in apport/hookutils.py function read_file().
local
low complexity
canonical CWE-22
5.5
2021-06-12 CVE-2021-32556 OS Command Injection vulnerability in Canonical Apport
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
local
low complexity
canonical CWE-78
3.3
2021-06-12 CVE-2021-32557 Link Following vulnerability in Canonical Apport
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
local
low complexity
canonical CWE-59
7.1
2021-06-11 CVE-2021-25682 Injection vulnerability in Canonical Apport
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
local
low complexity
canonical CWE-74
7.8
2021-06-11 CVE-2021-25683 Improper Input Validation vulnerability in Canonical Apport
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
local
low complexity
canonical CWE-20
7.8
2021-06-11 CVE-2021-25684 Improper Input Validation vulnerability in Canonical Apport
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
local
low complexity
canonical CWE-20
7.8
2020-08-06 CVE-2020-15702 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Canonical Apport
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code.
local
high complexity
canonical CWE-367
7.0
2020-08-06 CVE-2020-15701 Improper Handling of Exceptional Conditions vulnerability in Canonical Apport
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service.
local
low complexity
canonical CWE-755
5.5