Vulnerabilities > Canonical > Apport > 2.20.11.0ubuntu27.12

DATE CVE VULNERABILITY TITLE RISK
2021-10-01 CVE-2021-3709 Path Traversal vulnerability in Canonical Apport
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file.
local
low complexity
canonical CWE-22
5.5
2021-10-01 CVE-2021-3710 Path Traversal vulnerability in Canonical Apport
An information disclosure via path traversal was discovered in apport/hookutils.py function read_file().
4.7
2021-06-12 CVE-2021-32556 OS Command Injection vulnerability in Canonical Apport
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
local
low complexity
canonical CWE-78
2.1
2021-06-12 CVE-2021-32557 Link Following vulnerability in Canonical Apport
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
local
low complexity
canonical CWE-59
3.6
2021-06-11 CVE-2021-25682 Injection vulnerability in Canonical Apport
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
local
low complexity
canonical CWE-74
7.2
2021-06-11 CVE-2021-25683 Improper Input Validation vulnerability in Canonical Apport
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
local
low complexity
canonical CWE-20
7.2
2021-06-11 CVE-2021-25684 Improper Input Validation vulnerability in Canonical Apport
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
local
low complexity
canonical CWE-20
4.6