SB2023041410 - Ubuntu update for apport
Published: April 14, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Privilege Management (CVE-ID: CVE-2023-1326)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper privilege management in apport-cli. A local user can escalate privileges on a system that is specially configured to allow unprivileged users to run sudo apport-cli, when less is configured as the pager, and the terminal size can be set.
Remediation
Install update from vendor's website.