cbcvebase.
CVE-2021-32557
published 2021-06-12

CVE-2021-32557: It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

Affected

12 ranges
VendorProductVersion rangeFixed in
apport_projectapport>= 0 < 2.20.9-0ubuntu7.242.20.9-0ubuntu7.24
apport_projectapport>= 0 < 2.20.11-0ubuntu27.182.20.11-0ubuntu27.18
apport_projectapport>= 0 < 2.14.1-0ubuntu3.29+esm72.14.1-0ubuntu3.29+esm7
apport_projectapport>= 0 < 2.20.1-0ubuntu2.30+esm12.20.1-0ubuntu2.30+esm1
canonicalapport>= 2.14.1-0ubuntu3 < 2.14.1-0ubuntu3.29+esm72.14.1-0ubuntu3.29+esm7
canonicalapport>= 2.14.1-0ubuntu3 < 2.14.1-0ubuntu3.29\+esm72.14.1-0ubuntu3.29\+esm7
canonicalapport>= 2.20.1 < 2.20.1-0ubuntu2.30+esm12.20.1-0ubuntu2.30+esm1
canonicalapport>= 2.20.1 < 2.20.1-0ubuntu2.30\+esm12.20.1-0ubuntu2.30\+esm1
canonicalapport>= 2.20.11-0ubuntu27 < 2.20.11-0ubuntu27.182.20.11-0ubuntu27.18
canonicalapport>= 2.20.11-0ubuntu50 < 2.20.11-0ubuntu50.72.20.11-0ubuntu50.7
canonicalapport>= 2.20.11-0ubuntu65 < 2.20.11-0ubuntu65.12.20.11-0ubuntu65.1
canonicalapport>= 2.20.9 < 2.20.9-0ubuntu7.242.20.9-0ubuntu7.24

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv7.1HIGH