First published: Wed Oct 30 2019(Updated: )
Kevin Backhouse discovered Whoopsie incorrectly handled very large crash reports. A local attacker could possibly use this issue to cause a denial of service, expose sensitive information or execute code as the whoopsie user.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libwhoopsie0 | <0.2.66ubuntu0.1 | 0.2.66ubuntu0.1 |
Ubuntu | =19.10 | |
All of | ||
ubuntu/whoopsie | <0.2.66ubuntu0.1 | 0.2.66ubuntu0.1 |
Ubuntu | =19.10 | |
All of | ||
ubuntu/libwhoopsie0 | <0.2.64ubuntu0.2 | 0.2.64ubuntu0.2 |
Ubuntu | =19.04 | |
All of | ||
ubuntu/whoopsie | <0.2.64ubuntu0.2 | 0.2.64ubuntu0.2 |
Ubuntu | =19.04 | |
All of | ||
ubuntu/libwhoopsie0 | <0.2.62ubuntu0.2 | 0.2.62ubuntu0.2 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/whoopsie | <0.2.62ubuntu0.2 | 0.2.62ubuntu0.2 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libwhoopsie0 | <0.2.52.5ubuntu0.2 | 0.2.52.5ubuntu0.2 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/whoopsie | <0.2.52.5ubuntu0.2 | 0.2.52.5ubuntu0.2 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-4170-1 is critical due to its potential for denial of service, information exposure, and arbitrary code execution.
To fix USN-4170-1, upgrade the affected packages to the specified versions for your Ubuntu release.
USN-4170-1 affects Whoopsie, specifically the libwhoopsie0 and whoopsie packages on Ubuntu versions 16.04, 18.04, 19.04, and 19.10.
The vulnerability identified by USN-4170-1 was discovered by Kevin Backhouse.
An attacker can exploit the vulnerability in USN-4170-1 to cause a denial of service, expose sensitive information, or execute code as the whoopsie user.