CVE-2019-11476

MEDIUM

whoopsie <0.2.52.5ubuntu0.1-0.2.66 - Memory Corruption

Title source: llm
STIX 2.1

Description

An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the whoopsie process.

References (3)

Core 3

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 27.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-190
Status published
Products (4)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
canonical/ubuntu_linux 19.04
Published Aug 29, 2019
Tracked Since Feb 18, 2026