CVE-2013-1067: Medium severity Ubuntu vulnerability
Published Oct 25, 2013
·Updated
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
Affected Software
4 affected components
Ubuntu=12.04
Ubuntu=12.10
Ubuntu=13.04
Ubuntu=13.10
Event History
Oct 25, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1067?
CVE-2013-1067 is rated as medium severity due to the potential exposure of sensitive information by local users.
2
How do I fix CVE-2013-1067?
To fix CVE-2013-1067, update to a version of Ubuntu that includes the patch for Apport, specifically versions after 2.12.5.
3
Who is affected by CVE-2013-1067?
CVE-2013-1067 affects local users of Ubuntu Linux versions 12.04, 12.10, 13.04, and 13.10.
4
What type of attack does CVE-2013-1067 enable?
CVE-2013-1067 enables local users to access sensitive information through improperly secured core dump files.
5
Is CVE-2013-1067 a remote vulnerability?
No, CVE-2013-1067 is a local vulnerability that requires an authenticated user to exploit.