USN-3480-1
Dashboard / Vulnerabilities / USN-3480-1
USN-3480-1
Summary: apport vulnerabilities
Details: Sander Bos discovered that Apport incorrectly handled core dumps for setuid binaries. A local attacker could use this issue to perform a denial of service via resource exhaustion or possibly gain root privileges. (CVE-2017-14177) Sander Bos discovered that Apport incorrectly handled core dumps for processes in a different PID namespace. A local attacker could use this issue to perform a denial of service via resource exhaustion or possibly gain root privileges. (CVE-2017-14180)
References: https://ubuntu.com/security/notices/USN-3480-1, https://ubuntu.com/security/CVE-2017-14177, https://ubuntu.com/security/CVE-2017-14180
Affected packages
Package
Name: apport
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
