First published: Tue Feb 02 2021(Updated: )
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Apport | >=2.20.1-0ubuntu1<2.20.1-0ubuntu2.30 | |
Canonical Apport | >=2.20.9-0ubuntu1<2.20.9-0ubuntu7.23 | |
Canonical Apport | >=2.20.11-0ubuntu27<2.20.11-0ubuntu27.16 | |
Canonical Apport | >=2.20.11-0ubuntu50<2.20.11-0ubuntu50.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-25684 is high with a score of 7.8.
The affected software for CVE-2021-25684 is Canonical Apport versions 2.20.1-0ubuntu2.30 to 2.20.1-0ubuntu1, 2.20.9-0ubuntu7.23 to 2.20.9-0ubuntu1, 2.20.11-0ubuntu27.16 to 2.20.11-0ubuntu27, and 2.20.11-0ubuntu50.5 to 2.20.11-0ubuntu50.
CVE-2021-25684 is a vulnerability in apport that allows hanging reads on a FIFO due to improper opening of a report file.
Yes, a fix is available for CVE-2021-25684. It is recommended to update to the latest version of Canonical Apport.
More information about CVE-2021-25684 can be found at the following link: https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1912326