It was discovered that process_crash() in data/apport in Canonicals Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Apport | Canonical | 2.20.1-0ubuntu1 (including) | 2.20.1-0ubuntu2.30 (excluding) |
| Apport | Canonical | 2.20.9-0ubuntu7 (including) | 2.20.9-0ubuntu7.29 (excluding) |
| Apport | Canonical | 2.20.11-0ubuntu27 (including) | 2.20.11-0ubuntu27.28 (excluding) |
| Apport | Canonical | 2.20.11-0ubuntu82 (including) | 2.20.11-0ubuntu82.7 (excluding) |
| Apport | Canonical | 2.28.1-0ubuntu1 (including) | 2.28.1-0ubuntu3.6 (excluding) |
| Apport | Canonical | 2.32.0-0ubuntu1 (including) | 2.32.0-0ubuntu5.1 (excluding) |