Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: canonical
Published: 2018-02-02T14:00:00Z
Updated: 2024-09-17T00:15:35.899Z
Reserved: 2017-09-07T00:00:00
Link: CVE-2017-14177
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2018-02-02T14:29:00.263
Modified: 2018-02-15T13:20:49.943
Link: CVE-2017-14177
Redhat
No data.