CVE-2021-32557: apport process_report() arbitrary file write
It was discovered that the processreport() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32557?
CVE-2021-32557 is a vulnerability in Canonical Apport that allows arbitrary file writes via symlinks.
What is the severity of CVE-2021-32557?
CVE-2021-32557 has a severity of 7.1 (high).
How does CVE-2021-32557 affect Canonical Apport?
CVE-2021-32557 affects Canonical Apport versions between 2.14.1-0ubuntu3 and 2.14.1-0ubuntu3.29+esm7, 2.20.1-0ubuntu2 and 2.20.1-0ubuntu2.30+esm1, 2.20.9 and 2.20.9-0ubuntu7.24, 2.20.11-0ubuntu27 and 2.20.11-0ubuntu27.18, 2.20.11-0ubuntu50 and 2.20.11-0ubuntu50.7, and 2.20.11-0ubuntu65 and 2.20.11-0ubuntu65.1.
How can arbitrary file writes be performed via symlinks in CVE-2021-32557?
The process_report() function in data/whoopsie-upload-all allows attackers to perform arbitrary file writes by creating specially crafted symlinks.
Is there a fix for CVE-2021-32557?
Yes, updating Canonical Apport to versions after the mentioned vulnerable versions will fix CVE-2021-32557.