USN-4051-2: Apport vulnerability
USN-4051-1 fixed a vulnerability in apport. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Kevin Backhouse discovered a race-condition when reading the user's local Apport configuration. This could be used by a local attacker to cause Apport to include arbitrary files in a resulting crash report.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-4051-2?
USN-4051-2 addresses a race condition vulnerability that could allow a local attacker to exploit the user's Apport configuration.
How do I fix USN-4051-2?
To fix USN-4051-2, upgrade the python-apport and python3-apport packages to version 2.14.1-0ubuntu3.29+esm1 on Ubuntu 14.04.
What products are affected by USN-4051-2?
USN-4051-2 particularly affects Ubuntu 14.04 systems that have the python-apport and python3-apport packages installed.
Who discovered the vulnerability in USN-4051-2?
The vulnerability in USN-4051-2 was discovered by researcher Kevin Backhouse.
Is USN-4051-2 applicable to newer versions of Ubuntu?
No, USN-4051-2 is specifically relevant only to Ubuntu 14.04 ESM.