CVE-2017-6507
published 2017-03-24CVE-2017-6507: An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.59%
72.8th percentile
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apparmor | apparmor | <= 2.11 | — |
| apparmor | apparmor | >= 0 < 2.11.0-3 | 2.11.0-3 |
| apparmor | apparmor | >= 0 < 2.11.0-3 | 2.11.0-3 |
| apparmor | apparmor | >= 0 < 2.11.0-3 | 2.11.0-3 |
| apparmor | apparmor | >= 0 < 2.11.0-3 | 2.11.0-3 |
| canonical | ubuntu_core | — | — |
| canonical | ubuntu_touch | — | — |
| debian | apparmor | < apparmor 2.11.0-3 (bookworm) | apparmor 2.11.0-3 (bookworm) |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44p8-9hqx-3rqg: An issue was discovered in AppArmor before 2
ghsa_unreviewed·2022-05-13
CVE-2017-6507 [MEDIUM] CWE-269 GHSA-44p8-9hqx-3rqg: An issue was discovered in AppArmor before 2
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
OSV
CVE-2017-6507: An issue was discovered in AppArmor before 2
osv·2017-03-24·CVSS 5.9
CVE-2017-6507 [MEDIUM] CVE-2017-6507: An issue was discovered in AppArmor before 2
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
Ubuntu
AppArmor vulnerability
vendor_ubuntu·2017-03-28
CVE-2017-6507 AppArmor vulnerability
Title: AppArmor vulnerability
Summary: AppArmor could remove the confinement from some programs.
Stéphane Graber discovered that AppArmor incorrectly unloaded some profiles
when restarted or upgraded, contrary to expected behavior.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
A new utility, called aa-remove-unknown, was added to assist with profiles that
would have been previously unloaded when AppArmor was restarted or upgraded.
Debian
CVE-2017-6507: apparmor - An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown A...
vendor_debian·2017·CVSS 5.9
CVE-2017-6507 [MEDIUM] CVE-2017-6507: apparmor - An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown A...
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
Scope: local
bookworm: resolved (fixed in 2.11.0-3)
bullseye: resolved (fixed in 2.11.0-3)
forky: resolved (fixed in 2.11.0-3)
sid: resolved (fixed in 2.11.0-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3647http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3648http://www.securityfocus.com/bid/97223https://bugs.launchpad.net/apparmor/+bug/1668892https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6507.htmlhttp://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3647http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3648http://www.securityfocus.com/bid/97223https://bugs.launchpad.net/apparmor/+bug/1668892https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6507.html
2017-03-24
Published