CVE-2017-14177Uncontrolled Resource Consumption in Project Apport

Severity
7.8HIGHNVD
EPSS
0.1%
top 83.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 2
Latest updateMay 14

Description

Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Ubuntuapport_project/apport< 2.14.1-0ubuntu3.27+3
CVEListV5apport_project/apportthrough 2.20.7

Also affects: Ubuntu Linux 14.04, 16.04, 17.04, 17.10, 18.04

🔴Vulnerability Details

6
GHSA
GHSA-gx65-cr2w-3vfm: Apport through 22022-05-14
CVEList
CVE-2017-14177: Apport through 22018-02-02
OSV
apport regression2018-01-03
OSV
apport regressions2017-11-20
OSV
apport vulnerabilities2017-11-15

📋Vendor Advisories

2
Ubuntu
Apport regressions2017-11-20
Ubuntu
Apport vulnerabilities2017-11-15
CVE-2017-14177 — Uncontrolled Resource Consumption | cvebase