CVE-2015-1318

Apport <2.17.1 - Privilege Escalation

Title source: llm

Description

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/43971
exploitdb WORKING POC
by Ricardo F. Teixeira · bashlocallinux
https://www.exploit-db.com/exploits/36782
nomisec WORKING POC 4 stars
by ScottyBauer · poc
https://github.com/ScottyBauer/CVE-2015-1318
exploitdb WORKING POC
clocallinux
https://www.exploit-db.com/exploits/36746
metasploit WORKING POC EXCELLENT
by Stéphane Graber, Tavis Ormandy, Ricardo F. Teixeira, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/apport_abrt_chroot_priv_esc.rb

Scores

EPSS 0.1907
EPSS Percentile 95.4%

Details

CWE
CWE-264
Status published
Products (18)
apport_project/apport 2.13
apport_project/apport 2.13.1
apport_project/apport 2.13.2
apport_project/apport 2.13.3
apport_project/apport 2.14
apport_project/apport 2.14.1
apport_project/apport 2.14.2
apport_project/apport 2.14.3
apport_project/apport 2.14.4
apport_project/apport 2.14.5
... and 8 more
Published Apr 17, 2015
Tracked Since Feb 18, 2026