First published: Tue Jun 04 2024(Updated: )
is_closing_session() allows users to fill up apport.log
Credit: security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Python 3 Apport | <2.21.0 | |
Ubuntu | =18.04 | |
Ubuntu | =20.04 | |
Ubuntu | =21.10 | |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28654 is classified as a high-severity vulnerability affecting multiple versions of Apport in Ubuntu.
To fix CVE-2022-28654, users should update Apport to version 2.21.0 or later.
CVE-2022-28654 affects Apport running on Ubuntu 18.04, 20.04, 21.10, and 22.04.
CVE-2022-28654 exploits an issue in the is_closing_session() function that can lead to excessive logging in apport.log.
Currently, the recommended approach is to apply the necessary updates to mitigate CVE-2022-28654 effectively.