Vulnerabilities > Canonical > Apport > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-01 CVE-2021-3709 Path Traversal vulnerability in Canonical Apport
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file.
local
low complexity
canonical CWE-22
5.5
2021-10-01 CVE-2021-3710 Path Traversal vulnerability in Canonical Apport
An information disclosure via path traversal was discovered in apport/hookutils.py function read_file().
4.7
2021-06-11 CVE-2021-25684 Improper Input Validation vulnerability in Canonical Apport
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
local
low complexity
canonical CWE-20
4.6
2020-08-06 CVE-2020-15701 Improper Handling of Exceptional Conditions vulnerability in Canonical Apport
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service.
local
low complexity
canonical CWE-755
5.5