PT-2016-7887 · Canonical · Apport-Gtk+2

Donncha Ocearbhaill

·

Publicado

2016-12-14

·

Atualizado

2017-01-07

·

CVE-2016-9951

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apport versions prior to 2.20.4
Description An issue was discovered where a malicious Apport crash file can contain a restart command in RespawnCommand or ProcCmdline fields, which will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file.
Recommendations For Apport versions prior to 2.20.4, the fix is to only show the Relaunch button on Apport crash files generated by local systems, and hide the Relaunch button when crash files are opened directly in Apport-GTK.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9951
USN-3157-1

Produtos afetados

Apport
Apport-Gtk
Ubuntu