CVE-2021-32556: apport get_modified_conffiles() function command injection
It was discovered that the getmodifiedconffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-32556.
What is the severity of CVE-2021-32556?
The severity of CVE-2021-32556 is low.
Which software is affected by CVE-2021-32556?
The Canonical Apport software with versions between 2.14.1-0ubuntu3 and 2.14.1-0ubuntu3.29+esm7, 2.20.1-0ubuntu2 and 2.20.1-0ubuntu2.30+esm1, 2.20.9 and 2.20.9-0ubuntu7.24, 2.20.11-0ubuntu27 and 2.20.11-0ubuntu27.18, 2.20.11-0ubuntu50 and 2.20.11-0ubuntu50.7, and 2.20.11-0ubuntu65 and 2.20.11-0ubuntu65.1 are affected.
How can CVE-2021-32556 be exploited?
CVE-2021-32556 can be exploited by injecting modified package names in a manner that would confuse the dpkg(1) call.
Is there a reference link for CVE-2021-32556?
Yes, you can find more information about CVE-2021-32556 at the following link: https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1917904