cbcvebase.
CVE-2021-25682
published 2021-06-11

CVE-2021-25682: It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

Affected

10 ranges
VendorProductVersion rangeFixed in
apport_projectapport>= 0 < 2.20.1-0ubuntu2.302.20.1-0ubuntu2.30
apport_projectapport>= 0 < 2.20.9-0ubuntu7.232.20.9-0ubuntu7.23
apport_projectapport>= 0 < 2.20.11-0ubuntu27.162.20.11-0ubuntu27.16
apport_projectapport>= 0 < 2.14.1-0ubuntu3.29+esm62.14.1-0ubuntu3.29+esm6
canonicalapport>= 2.20.1 < 2.20.1-0ubuntu2.302.20.1-0ubuntu2.30
canonicalapport>= 2.20.1-0ubuntu1 < 2.20.1-0ubuntu2.302.20.1-0ubuntu2.30
canonicalapport>= 2.20.11-0ubuntu27 < 2.20.11-0ubuntu27.162.20.11-0ubuntu27.16
canonicalapport>= 2.20.11-0ubuntu50 < 2.20.11-0ubuntu50.52.20.11-0ubuntu50.5
canonicalapport>= 2.20.9 < 2.20.9-0ubuntu7.232.20.9-0ubuntu7.23
canonicalapport>= 2.20.9-0ubuntu1 < 2.20.9-0ubuntu7.232.20.9-0ubuntu7.23

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH