PT-2017-3610 · Canonical+1 · Apport+1
Sander Bos
·
Published
2017-10-21
·
Updated
2025-11-03
·
CVE-2017-14179
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apport versions prior to 2.13
Description:
The issue is related to uncontrolled resource consumption in the Apport error reporting software in the Ubuntu operating system. Exploitation of this issue could allow an attacker to cause a denial of service, escape from Linux Containers (LXC), or gain root privileges by leveraging files that Apport can create as root in the event of a crash. This can be achieved by local users creating certain files as root, which can then be used to perform malicious actions.
Recommendations:
For Apport versions prior to 2.13, update to version 2.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of Apport to minimize the risk of exploitation. Avoid using Apport in environments where it can be exploited by local users until the issue is resolved.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apport
Linux Containers