USN-3480-2

    Dashboard / Vulnerabilities / USN-3480-2

    USN-3480-2

    Published: 20 Nov 2017Last Modified: 10 Feb 2026

    Summary: apport regressions

    Details: USN-3480-1 fixed vulnerabilities in Apport. The fix for CVE-2017-14177 introduced a regression in the ability to handle crashes for users that configured their systems to use the Upstart init system in Ubuntu 16.04 LTS and Ubuntu 17.04. The fix for CVE-2017-14180 temporarily disabled crash forwarding to containers. This update addresses the problems. We apologize for the inconvenience. Original advisory details: Sander Bos discovered that Apport incorrectly handled core dumps for setuid binaries. A local attacker could use this issue to perform a denial of service via resource exhaustion or possibly gain root privileges. (CVE-2017-14177) Sander Bos discovered that Apport incorrectly handled core dumps for processes in a different PID namespace. A local attacker could use this issue to perform a denial of service via resource exhaustion or possibly gain root privileges. (CVE-2017-14180)

    Affected packages

    Package

    Name: apport

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.20.1-0ubuntu2.13

    Affected versions

    2.19.1-0ubuntu3
    2.19.2-0ubuntu1
    2.19.2-0ubuntu2
    2.19.2-0ubuntu3
    2.19.2-0ubuntu4
    2.19.2-0ubuntu5
    2.19.2-0ubuntu6
    2.19.2-0ubuntu8
    2.19.2-0ubuntu9
    2.19.3-0ubuntu1
    2.19.3-0ubuntu2
    2.19.3-0ubuntu3
    2.19.4-0ubuntu1
    2.19.4-0ubuntu2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High