CVE-2019-11483

HIGH

Apport - Unprotected Privileged Process Crash Report Exposure via Container Crash Dump

Title source: llm
STIX 2.1

Description

Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://usn.ubuntu.com/usn/usn-4171-1
Third Party Advisory x_refsource_misc
https://usn.ubuntu.com/usn/usn-4171-2

Scores

CVSS v3 7.0
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L

Details

Status published
Products (6)
apport_project/apport
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.04
canonical/ubuntu_linux 19.10
Published Feb 08, 2020
Tracked Since Feb 18, 2026