USN-4051-1: Apport vulnerability
Published Jul 9, 2019
·Updated
Kevin Backhouse discovered a race-condition when reading the user's local Apport configuration. This could be used by a local attacker to cause Apport to include arbitrary files in a resulting crash report.
Affected Software
16 affected componentsFixes available
All of the following
ubuntu/python-apport<2.20.10-0ubuntu27.1
2.20.10-0ubuntu27.1
Ubuntu Ubuntu=19.04
All of the following
ubuntu/python3-apport<2.20.10-0ubuntu27.1
2.20.10-0ubuntu27.1
Ubuntu Ubuntu=19.04
All of the following
ubuntu/python-apport<2.20.10-0ubuntu13.4
2.20.10-0ubuntu13.4
Ubuntu Ubuntu=18.10
All of the following
ubuntu/python3-apport<2.20.10-0ubuntu13.4
2.20.10-0ubuntu13.4
Ubuntu Ubuntu=18.10
All of the following
ubuntu/python-apport<2.20.9-0ubuntu7.7
2.20.9-0ubuntu7.7
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python3-apport<2.20.9-0ubuntu7.7
2.20.9-0ubuntu7.7
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python-apport<2.20.1-0ubuntu2.19
2.20.1-0ubuntu2.19
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python3-apport<2.20.1-0ubuntu2.19
2.20.1-0ubuntu2.19
Ubuntu Ubuntu=16.04
Event History
Jul 9, 2019
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-4051-1?
The severity of USN-4051-1 is considered to be moderate due to potential risks related to local privilege escalation.
2
How do I fix USN-4051-1?
To fix USN-4051-1, you should upgrade to the latest version of the affected packages, such as python-apport or python3-apport.
3
Who discovered the vulnerability USN-4051-1?
The vulnerability USN-4051-1 was discovered by Kevin Backhouse.
4
What versions of Ubuntu are affected by USN-4051-1?
Ubuntu versions 16.04, 18.04, 18.10, and 19.04 are affected by USN-4051-1.
5
Can USN-4051-1 be exploited remotely?
No, USN-4051-1 cannot be exploited remotely as it requires local access to the system.