Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-7307
Description:Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allows a local attacker to replace this file with a symlink to any other file on the system and so cause Apport to include the contents of this other file in the resulting crash report. The crash report could then be read by that user either by causing it to be uploaded and reported to Launchpad, or by leveraging some other vulnerability to read the resulting crash report, and so allow the user to read arbitrary files on the system.
Test IDs: 1.3.6.1.4.1.25623.1.0.844085   1.3.6.1.4.1.25623.1.1.12.2019.4051.2  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-7307
http://packetstormsecurity.com/files/172858/Ubuntu-Apport-Whoopsie-DoS-Integer-Overflow.html
https://bugs.launchpad.net/ubuntu/%2Bsource/apport/%2Bbug/1830858
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-7307.html




© 1998-2025 E-Soft Inc. All rights reserved.