CVE-2016-9949
HIGHApport < 2.20.4 - Remote Code Execution via CrashDB Field Evaluation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-9949. PoCs published by Donncha OCearbhaill.
AI-analyzed exploit summary This is a writeup discussing multiple vulnerabilities in Apport, including CVE-2016-9951, which allows arbitrary command execution via the 'Relaunch' action. The text provides context, links to fixes, and encourages responsible disclosure.
Description
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
Exploits (1)
This is a writeup discussing multiple vulnerabilities in Apport, including CVE-2016-9951, which allows arbitrary command execution via the 'Relaunch' action. The text provides context, links to fixes, and encourages responsible disclosure.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H