First published: Thu Apr 30 2009(Updated: )
Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Python 3 Apport | <=0.1.0.8.1 | |
Ubuntu | =8.0.4_lts | |
Ubuntu | =8.1.0 | |
Ubuntu | =9.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1295 is considered a moderate severity vulnerability due to its potential for local users to delete arbitrary files.
To fix CVE-2009-1295, update to Apport versions 0.108.4 on Ubuntu 8.04 LTS, 0.119.2 on Ubuntu 8.10, or 1.0-0ubuntu5.2 on Ubuntu 9.04.
CVE-2009-1295 affects users of Apport on Ubuntu versions 8.04 LTS, 8.10, and 9.04.
CVE-2009-1295 is a local file deletion vulnerability caused by improper handling of crash reports.
CVE-2009-1295 cannot be exploited remotely as it requires local user access to exploit the vulnerability.