CVE-2021-25683: apport improperly parses /proc/pid/stat
It was discovered that the getstarttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25683?
CVE-2021-25683 is a vulnerability that affects the get_starttime() function in data/apport, which does not properly parse the /proc/pid/stat file from the kernel.
Which software is affected by CVE-2021-25683?
The Canonical Apport software versions 2.20.1-0ubuntu1 to 2.20.1-0ubuntu2.30, 2.20.9-0ubuntu1 to 2.20.9-0ubuntu7.23, 2.20.11-0ubuntu27 to 2.20.11-0ubuntu27.16, and 2.20.11-0ubuntu50 to 2.20.11-0ubuntu50.5 are affected by CVE-2021-25683.
What is the severity of CVE-2021-25683?
CVE-2021-25683 has a severity rating of 7.8 (High).
How can I fix the CVE-2021-25683 vulnerability?
To fix the CVE-2021-25683 vulnerability, update the Canonical Apport software to versions higher than the affected ones.
Where can I find more information about CVE-2021-25683?
You can find more information about CVE-2021-25683 at the following link: [https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1912326](https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1912326)