#VU22533 Permissions, Privileges, and Access Controls in apport (Ubuntu package) - CVE-2019-15790
Published: November 5, 2019 / Updated: July 20, 2020
apport (Ubuntu package)
Canonical Ltd.
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to Apport reads various process-specific files with elevated privileges during crash dump generation. A local user can force the application to generate a crash report for a privileged process and gain access to sensitive information.
Remediation
- Ubuntu 19.10
- apport - 2.20.11-0ubuntu8.2
- python-apport - 2.20.11-0ubuntu8.2
- python3-apport - 2.20.11-0ubuntu8.2
- Ubuntu 19.04
- apport - 2.20.10-0ubuntu27.3
- python-apport - 2.20.10-0ubuntu27.3
- python3-apport - 2.20.10-0ubuntu27.3
- Ubuntu 18.04 LTS
- apport - 2.20.9-0ubuntu7.9
- python-apport - 2.20.9-0ubuntu7.9
- python3-apport - 2.20.9-0ubuntu7.9
- Ubuntu 16.04 LTS
- apport - 2.20.1-0ubuntu2.21
- python-apport - 2.20.1-0ubuntu2.21
- python3-apport - 2.20.1-0ubuntu2.21