CVE-2015-1318

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
apport_projectapport
2.13
apport_projectapport
2.13.1
apport_projectapport
2.13.2
apport_projectapport
2.13.3
apport_projectapport
2.14
apport_projectapport
2.14.1
apport_projectapport
2.14.2
apport_projectapport
2.14.3
apport_projectapport
2.14.4
apport_projectapport
2.14.5
apport_projectapport
2.14.6
apport_projectapport
2.14.7
apport_projectapport
2.15
apport_projectapport
2.15.1
apport_projectapport
2.16
apport_projectapport
2.16.1
apport_projectapport
2.16.2
apport_projectapport
2.17
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apport
utopic
Fixed 2.14.7-0ubuntu8.3
released
trusty
Fixed 2.14.1-0ubuntu3.9
released
precise
not-affected
lucid
not-affected
Common Weakness Enumeration