Security features bypass in python3-apport (Ubuntu package) and apport (Ubuntu package) - CVE-2022-28657
Published: May 18, 2022 / Updated: May 19, 2022
python3-apport (Ubuntu package)
apport (Ubuntu package)
Canonical Ltd.
Description
The vulnerability allows a local user to execute arbitrary code with escalated privileges.
The vulnerability exists due to Apport does not disable the python crash handler before chrooting into a container. A local user can bypass implemented security restrictions and execute arbitrary code with escalated privileges.