Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-9951
Description:An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file. The fix is to only show the Relaunch button on Apport crash files generated by local systems. The Relaunch button will be hidden when crash files are opened directly in Apport-GTK.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-9951
BugTraq ID: 95011
http://www.securityfocus.com/bid/95011
https://www.exploit-db.com/exploits/40937/
https://bugs.launchpad.net/apport/+bug/1648806
https://donncha.is/2016/12/compromising-ubuntu-desktop/
https://github.com/DonnchaC/ubuntu-apport-exploitation
http://www.ubuntu.com/usn/USN-3157-1




© 1998-2025 E-Soft Inc. All rights reserved.