Canonical Apport vulnerabilities
32 known vulnerabilities affecting canonical/apport.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM16LOW5
Vulnerabilities
Page 2 of 2
CVE-2021-32553P4MEDIUMCVSS 5.5≥ 2.20.1, < 2.20.1-0ubuntu2.30+esm1≥ 2.20.9, < 2.20.9-0ubuntu7.24+4 more2021-06-12
CVE-2021-32553 [MEDIUM] CWE-59 CVE-2021-32553: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs.
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32547P4MEDIUMCVSS 5.5≥ 2.20.1, < 2.20.1-0ubuntu2.30+esm1≥ 2.20.9, < 2.20.9-0ubuntu7.24+4 more2021-06-12
CVE-2021-32547 [MEDIUM] CWE-59 CVE-2021-32547: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs.
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32548P4MEDIUMCVSS 5.5≥ 2.20.1, < 2.20.1-0ubuntu2.30+esm1≥ 2.20.9, < 2.20.9-0ubuntu7.24+4 more2021-06-12
CVE-2021-32548 [MEDIUM] CWE-59 CVE-2021-32548: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs.
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32550P4MEDIUMCVSS 5.5≥ 2.20.1, < 2.20.1-0ubuntu2.30+esm1≥ 2.20.9, < 2.20.9-0ubuntu7.24+4 more2021-06-12
CVE-2021-32550 [MEDIUM] CWE-59 CVE-2021-32550: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs.
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32554P4MEDIUMCVSS 5.5≥ 2.20.1, < 2.20.1-0ubuntu2.30+esm1≥ 2.20.9, < 2.20.9-0ubuntu7.24+4 more2021-06-12
CVE-2021-32554 [MEDIUM] CWE-59 CVE-2021-32554: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs.
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32552P4MEDIUMCVSS 5.5≥ 2.20.1, < 2.20.1-0ubuntu2.30+esm1≥ 2.20.9, < 2.20.9-0ubuntu7.24+4 more2021-06-12
CVE-2021-32552 [MEDIUM] CWE-59 CVE-2021-32552: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs.
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.
nvd
CVE-2020-15701P4MEDIUMCVSS 5.5v2.20.11-0ubuntu8v2.20.11-0ubuntu9+101 more2020-08-06
CVE-2020-15701 [MEDIUM] CWE-755 CVE-2020-15701: An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker t
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16, 2.20.11-0ubuntu27.6.
nvd
CVE-2019-15790P4LOWCVSS 3.3≥ 2.14.1, < 2.14.1-0ubuntu3.29+esm3≥ 2.20.1, < 2.20.1-0ubuntu2.22+2 more2020-04-28
CVE-2019-15790 [LOW] CWE-250 CVE-2019-15790: Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Appo
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read information about a privileged running process by exploiting PID recycling. This info
nvd
CVE-2025-5467P4LOWCVSS 3.3≥ 2.20.1-0ubuntu1, < 2.20.1-0ubuntu2.30≥ 2.20.9-0ubuntu7, < 2.20.9-0ubuntu7.29+9 more2025-12-10
CVE-2025-5467 [LOW] CWE-708 CVE-2025-5467: It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may
It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
nvd
CVE-2021-32556P4LOWCVSS 3.3≥ 2.14.1-0ubuntu3, < 2.14.1-0ubuntu3.29\+esm7≥ 2.20.1, < 2.20.1-0ubuntu2.30\+esm1+6 more2021-06-12
CVE-2021-32556 [LOW] CWE-78 CVE-2021-32556: It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allow
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
nvd
CVE-2019-11483P4LOWCVSS 3.3≥ 2.14.1, < 2.14.1-0ubuntu3.29+esm2≥ 2.20.1, < 2.20.1-0ubuntu2.20+2 more2020-02-08
CVE-2019-11483 [LOW] CVE-2019-11483: Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
nvd
CVE-2019-11485P4LOWCVSS 3.3≥ 2.14.1, < 2.14.1-0ubuntu3.29+esm2≥ 2.20.1, < 2.20.1-0ubuntu2.20+2 more2020-02-08
CVE-2019-11485 [LOW] CWE-412 CVE-2019-11485: Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users t
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
nvd
← Previous2 / 2