CVE Vulnerabilities

CVE-2015-1318

Published: Apr 17, 2015 | Modified: Feb 08, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
HIGH

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

Affected Software

Name Vendor Start Version End Version
Apport Apport_project 2.13 (including) 2.13 (including)
Apport Apport_project 2.13.1 (including) 2.13.1 (including)
Apport Apport_project 2.13.2 (including) 2.13.2 (including)
Apport Apport_project 2.13.3 (including) 2.13.3 (including)
Apport Apport_project 2.14 (including) 2.14 (including)
Apport Apport_project 2.14.1 (including) 2.14.1 (including)
Apport Apport_project 2.14.2 (including) 2.14.2 (including)
Apport Apport_project 2.14.3 (including) 2.14.3 (including)
Apport Apport_project 2.14.4 (including) 2.14.4 (including)
Apport Apport_project 2.14.5 (including) 2.14.5 (including)
Apport Apport_project 2.14.6 (including) 2.14.6 (including)
Apport Apport_project 2.14.7 (including) 2.14.7 (including)
Apport Apport_project 2.15 (including) 2.15 (including)
Apport Apport_project 2.15.1 (including) 2.15.1 (including)
Apport Apport_project 2.16 (including) 2.16 (including)
Apport Apport_project 2.16.1 (including) 2.16.1 (including)
Apport Apport_project 2.16.2 (including) 2.16.2 (including)
Apport Apport_project 2.17 (including) 2.17 (including)
Apport Ubuntu devel *
Apport Ubuntu trusty *
Apport Ubuntu utopic *

References