You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Apportversions2.13through2.17.xbefore2.17.1onUbuntuarevulnerable,duetoafeaturewhichallowsforwardingreportstoacontainer's Apport by changing the root directory before loading the crash report, causing `usr/share/apport/apport` within the crashed task'sdirectorytobeexecuted.
9
+
10
+
Similarly,FedoraisvulnerablewhenthekernelcrashhandlerisconfiguredtochangerootdirectorybeforeexecutingABRT,causing`usr/libexec/abrt-hook-ccpp`withinthecrashedtask's directory to be executed.
11
+
12
+
In both instances, the crash handler does not drop privileges, resulting in code execution as root.
13
+
14
+
* Apport 2.14.1 on Ubuntu 14.04.1 LTS x86 and x86_64
0 commit comments