Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 12.04 (including) | 12.04 (including) |
Ubuntu_linux | Canonical | 12.10 (including) | 12.10 (including) |
Ubuntu_linux | Canonical | 13.04 (including) | 13.04 (including) |
Ubuntu_linux | Canonical | 13.10 (including) | 13.10 (including) |
Apport | Ubuntu | devel | * |
Apport | Ubuntu | lucid | * |
Apport | Ubuntu | precise | * |
Apport | Ubuntu | quantal | * |
Apport | Ubuntu | raring | * |
Apport | Ubuntu | saucy | * |