CVE-2017-14177

HIGH

Apport <2.20.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.

References (4)

Core 4
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bazaar.launchpad.net/~apport-hackers/apport/trunk/revision/3171
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/usn/usn-3480-1
Issue Tracking, Third Party Advisory x_refsource_confirm
https://launchpad.net/bugs/1726372

Scores

CVSS v3 7.8
EPSS 0.0040
EPSS Percentile 31.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-400
Status published
Products (6)
apport_project/apport < 2.20.7
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 17.04
canonical/ubuntu_linux 17.10
canonical/ubuntu_linux 18.04
Published Feb 02, 2018
Tracked Since Feb 18, 2026