CVE-2019-7307
Summary
| CVE | CVE-2019-7307 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-29 15:15:00 UTC |
| Updated | 2023-06-12 07:15:00 UTC |
| Description | Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allows a local attacker to replace this file with a symlink to any other file on the system and so cause Apport to include the contents of this other file in the resulting crash report. The crash report could then be read by that user either by causing it to be uploaded and reported to Launchpad, or by leveraging some other vulnerability to read the resulting crash report, and so allow the user to read arbitrary files on the system. |
Risk And Classification
Problem Types: CWE-367
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apport Project | Apport | 2.14.1 | All | All | All |
| Application | Apport Project | Apport | 2.20.1 | All | All | All |
| Application | Apport Project | Apport | 2.20.10 | All | All | All |
| Application | Apport Project | Apport | 2.20.9 | All | All | All |
| Application | Apport Project | Apport | 2.14.1 | All | All | All |
| Application | Apport Project | Apport | 2.20.1 | All | All | All |
| Application | Apport Project | Apport | 2.20.10 | All | All | All |
| Application | Apport Project | Apport | 2.20.9 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ubuntu Apport / Whoopsie DoS / Integer Overflow ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Bug #1830858 “TOCTOU vulnerability in _get_ignore_dom (report.py...” : Bugs : apport package : Ubuntu | MISC | bugs.launchpad.net | Exploit, Issue Tracking, Vendor Advisory |
| CVE-2019-7307 | Ubuntu | MISC | people.canonical.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Kevin Backhouse of Semmle Security Research Team
There are currently no legacy QID mappings associated with this CVE.