CVE Vulnerabilities

CVE-2015-1318

Published: Apr 17, 2015 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

Affected Software

NameVendorStart VersionEnd Version
ApportApport_project2.13 (including)2.13 (including)
ApportApport_project2.13.1 (including)2.13.1 (including)
ApportApport_project2.13.2 (including)2.13.2 (including)
ApportApport_project2.13.3 (including)2.13.3 (including)
ApportApport_project2.14 (including)2.14 (including)
ApportApport_project2.14.1 (including)2.14.1 (including)
ApportApport_project2.14.2 (including)2.14.2 (including)
ApportApport_project2.14.3 (including)2.14.3 (including)
ApportApport_project2.14.4 (including)2.14.4 (including)
ApportApport_project2.14.5 (including)2.14.5 (including)
ApportApport_project2.14.6 (including)2.14.6 (including)
ApportApport_project2.14.7 (including)2.14.7 (including)
ApportApport_project2.15 (including)2.15 (including)
ApportApport_project2.15.1 (including)2.15.1 (including)
ApportApport_project2.16 (including)2.16 (including)
ApportApport_project2.16.1 (including)2.16.1 (including)
ApportApport_project2.16.2 (including)2.16.2 (including)
ApportApport_project2.17 (including)2.17 (including)
ApportUbuntudevel*
ApportUbuntuesm-infra-legacy/trusty*
ApportUbuntutrusty*
ApportUbuntutrusty/esm*
ApportUbuntuutopic*

References