CVE-2019-11485: apport created lock file in wrong directory
Published Feb 8, 2020
·Updated
Last updated 25 August 2025
Other sources
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
— Launchpad
Affected Software
6 affected components
Apport Project Apport
Ubuntu=14.04
Ubuntu=16.04
Ubuntu=18.04
Ubuntu=19.04
Ubuntu=19.10
Event History
Feb 8, 2020
CVE Published
via MITRE·04:50 AM
Data Sourced
via MITRE·04:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:14 PM
Description
Data Sourced
via Debian·11:14 PM
DescriptionAffected Software
Nov 6, 2025
Data Sourced
via Ubuntu·07:41 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-11485?
CVE-2019-11485 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2019-11485?
To fix CVE-2019-11485, update Apport to the latest version provided in your Linux distribution's repository.
3
What systems are affected by CVE-2019-11485?
CVE-2019-11485 affects multiple versions of Ubuntu Linux, specifically 14.04, 16.04, 18.04, 19.04, and 19.10.
4
What type of vulnerability is CVE-2019-11485?
CVE-2019-11485 is a directory permission vulnerability that can lead to improper crash handling.
5
Can CVE-2019-11485 be exploited remotely?
CVE-2019-11485 requires local access to the system, so it cannot be exploited remotely.