CVE-2015-1325

HIGH

Apport <2.17.2-0ubuntu1.1, <2.14.70ubuntu8.5, <2.14.1-0ubuntu3.11, ...

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-1325. PoCs published by rebel.

AI-analyzed exploit summary This exploit leverages a race condition in Apport (CVE-2015-1325) to achieve local privilege escalation on Ubuntu systems. It manipulates PID reuse and file handling to write a malicious core dump to /etc/sudoers.d, granting root access.

Description

Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges.

Exploits (1)

exploitdb WORKING POC
by rebel · clocallinux
https://www.exploit-db.com/exploits/37088

This exploit leverages a race condition in Apport (CVE-2015-1325) to achieve local privilege escalation on Ubuntu systems. It manipulates PID reuse and file handling to write a malicious core dump to /etc/sudoers.d, granting root access.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Apport on Ubuntu 14.04, 14.10, 15.04
No auth needed
Prerequisites: Local access to an Ubuntu system with Apport installed · Ability to execute binaries
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/05/21/10
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74769
Patch, Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2609-1
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37088/

Scores

CVSS v3 7.0
EPSS 0.0052
EPSS Percentile 67.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (4)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 14.10
canonical/ubuntu_linux 15.04
Published Aug 25, 2017
Tracked Since Feb 18, 2026