CVE-2013-1067
published 2013-10-25CVE-2013-1067: Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.40%
33.0th percentile
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apport vulnerability
vendor_ubuntu·2013-10-24
CVE-2013-1067 Apport vulnerability
Title: Apport vulnerability
Summary: Apport could be made to expose privileged information.
Martin Carpenter discovered that Apport set incorrect permissions on core
dump files generated by setuid binaries. A local attacker could possibly
use this issue to obtain privileged information.
Instructions: In general, a standard system update will make all the necessary changes.
GHSA
GHSA-8pvv-m49q-jr79: Apport 2
ghsa_unreviewed·2022-05-17
CVE-2013-1067 [MEDIUM] GHSA-8pvv-m49q-jr79: Apport 2
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-10-25
Published