CVE Vulnerabilities

CVE-2015-1341

Published: Apr 22, 2019 | Modified: May 07, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
HIGH

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Canonical 12.04 (including) 12.04 (including)
Ubuntu_linux Canonical 14.04 (including) 14.04 (including)
Ubuntu_linux Canonical 15.04 (including) 15.04 (including)
Ubuntu_linux Canonical 15.10 (including) 15.10 (including)
Apport Ubuntu devel *
Apport Ubuntu precise *
Apport Ubuntu trusty *
Apport Ubuntu vivid *
Apport Ubuntu vivid/stable-phone-overlay *
Apport Ubuntu wily *
Apport Ubuntu xenial *
Apport Ubuntu yakkety *
Apport Ubuntu zesty *

References