In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Whoopsie | Canonical | 0.2.66 (including) | 0.2.66 (including) |
Whoopsie | Canonical | 0.2.67 (including) | 0.2.67 (including) |
Whoopsie | Canonical | 0.2.68 (including) | 0.2.68 (including) |
Whoopsie | Canonical | 0.2.69 (including) | 0.2.69 (including) |
Whoopsie | Ubuntu | bionic | * |
Whoopsie | Ubuntu | devel | * |
Whoopsie | Ubuntu | eoan | * |
Whoopsie | Ubuntu | focal | * |
Whoopsie | Ubuntu | trusty | * |
Whoopsie | Ubuntu | xenial | * |