CVE Vulnerabilities

CVE-2019-11485

Unrestricted Externally Accessible Lock

Published: Feb 08, 2020 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Sander Bos discovered Apports lock file was in a world-writable directory which allowed all users to prevent crash handling.

Weakness

The product properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control.

Affected Software

Name Vendor Start Version End Version
Apport Apport_project - (including) - (including)
Apport Ubuntu bionic *
Apport Ubuntu devel *
Apport Ubuntu disco *
Apport Ubuntu eoan *
Apport Ubuntu trusty *
Apport Ubuntu trusty/esm *
Apport Ubuntu xenial *

Potential Mitigations

References