CVE-2016-9950
HIGHApport < 2.20.4 - Path Traversal via Package Hook Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-9950. PoCs published by Donncha OCearbhaill.
AI-analyzed exploit summary This is a writeup discussing multiple vulnerabilities in Apport, including CVE-2016-9951, which allows arbitrary command execution via the 'Relaunch' action. The text provides context, links to fixes, and encourages responsible disclosure.
Description
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.
Exploits (1)
This is a writeup discussing multiple vulnerabilities in Apport, including CVE-2016-9951, which allows arbitrary command execution via the 'Relaunch' action. The text provides context, links to fixes, and encourages responsible disclosure.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H