PT-2017-3610 · Canonical+1 · Apport+1
Sander Bos
·
Publicado
2017-10-21
·
Atualizado
2025-11-03
·
CVE-2017-14179
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apport versions prior to 2.13
Description:
The issue is related to uncontrolled resource consumption in the Apport error reporting software in the Ubuntu operating system. Exploitation of this issue could allow an attacker to cause a denial of service, escape from Linux Containers (LXC), or gain root privileges by leveraging files that Apport can create as root in the event of a crash. This can be achieved by local users creating certain files as root, which can then be used to perform malicious actions.
Recommendations:
For Apport versions prior to 2.13, update to version 2.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of Apport to minimize the risk of exploitation. Avoid using Apport in environments where it can be exploited by local users until the issue is resolved.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apport
Linux Containers