CVE-2019-11482: Race condition between reading current working directory and writing a core dump
Published Feb 8, 2020
·Updated
Last updated 25 August 2025
Other sources
Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.
— Launchpad
Affected Software
6 affected components
Ubuntu=14.04
Ubuntu=16.04
Ubuntu=18.04
Ubuntu=19.04
Ubuntu=19.10
Apport Project Apport
Event History
Feb 8, 2020
CVE Published
via MITRE·04:50 AM
Data Sourced
via MITRE·04:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:14 PM
Description
Data Sourced
via Debian·11:14 PM
DescriptionAffected Software
Nov 7, 2025
Data Sourced
via Ubuntu·07:43 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-11482?
CVE-2019-11482 has been rated as a medium severity vulnerability due to its potential to write core files in arbitrary directories.
2
How do I fix CVE-2019-11482?
To fix CVE-2019-11482, apply the latest patches provided by Ubuntu for the affected versions.
3
Which versions of Ubuntu are affected by CVE-2019-11482?
CVE-2019-11482 affects Ubuntu versions 14.04, 16.04, 18.04, 19.04, and 19.10.
4
What causes the vulnerability CVE-2019-11482?
CVE-2019-11482 is caused by a time of check to time of use (TOCTTOU) issue in the Apport error reporting system.
5
Can CVE-2019-11482 be exploited remotely?
CVE-2019-11482 requires local access to the system, thus it is not a remote exploitation vulnerability.