CVE-2013-1067

Ubuntu Linux - Information Disclosure via Weak Core Dump File Permissions

Title source: llm
STIX 2.1

Description

Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2007-1

Scores

EPSS 0.0040
EPSS Percentile 32.6%

Details

CWE
CWE-264
Status published
Products (4)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
Published Oct 25, 2013
Tracked Since Feb 18, 2026