CVE-2022-28652: Medium severity ubuntu python3-apport vulnerability
Published Jun 4, 2024
·Updated
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
Affected Software
5 affected components
Apport Project Apport<2.21.0
Ubuntu=18.04
Ubuntu=20.04
Ubuntu=21.10
Ubuntu=22.04
Event History
Jun 4, 2024
CVE Published
via MITRE·09:38 PM
Data Sourced
via MITRE·09:38 PM
Description
Jun 7, 2024
Data Sourced
via Debian·06:52 PM
DescriptionAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·06:57 PM
Description
Aug 22, 2025
Data Sourced
via Ubuntu·04:43 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-28652?
CVE-2022-28652 is considered a moderate severity vulnerability due to its potential for denial of service attacks.
2
How do I fix CVE-2022-28652?
To fix CVE-2022-28652, update the Apport utility to version 2.21.0 or later.
3
Which software is affected by CVE-2022-28652?
CVE-2022-28652 affects Apport versions prior to 2.21.0 and several Ubuntu Linux versions including 18.04, 20.04, 21.10, and 22.04.
4
What type of attack does CVE-2022-28652 enable?
CVE-2022-28652 can be exploited via a billion laughs attack, leading to potential denial of service.
5
When was CVE-2022-28652 last updated?
CVE-2022-28652 was last updated on July 24, 2024.