95011vdb entry
http://www.securityfocus.com/bid/95011 CVE-2016-9949
HIGH
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
Record summary
CVE-2016-9949 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code ExecutionExploitDB exploitby Donncha OCearbhaillNot analyzed1 file
References
7USN-3157-1Vendor advisory
http://www.ubuntu.com/usn/USN-3157-1 bugs.launchpad.net
https://bugs.launchpad.net/apport/+bug/1648806 donncha.is
https://donncha.is/2016/12/compromising-ubuntu-desktop github.com
https://github.com/DonnchaC/ubuntu-apport-exploitation nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-9949 40937exploit
https://www.exploit-db.com/exploits/40937