CVE-2020-15702
06.08.2020, 23:15
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges. Fixed in 2.20.1-0ubuntu2.24, 2.20.9 versions prior to 2.20.9-0ubuntu7.16 and 2.20.11 versions prior to 2.20.11-0ubuntu27.6. Was ZDI-CAN-11234.
Vendor | Product | Version |
---|---|---|
canonical | apport | 2.20.11-0ubuntu8 |
canonical | apport | 2.20.11-0ubuntu9 |
canonical | apport | 2.20.11-0ubuntu10 |
canonical | apport | 2.20.11-0ubuntu11 |
canonical | apport | 2.20.11-0ubuntu12 |
canonical | apport | 2.20.11-0ubuntu13 |
canonical | apport | 2.20.11-0ubuntu14 |
canonical | apport | 2.20.11-0ubuntu15 |
canonical | apport | 2.20.11-0ubuntu16 |
canonical | apport | 2.20.11-0ubuntu17 |
canonical | apport | 2.20.11-0ubuntu18 |
canonical | apport | 2.20.11-0ubuntu19 |
canonical | apport | 2.20.11-0ubuntu20 |
canonical | apport | 2.20.11-0ubuntu21 |
canonical | apport | 2.20.11-0ubuntu22 |
canonical | apport | 2.20.11-0ubuntu23 |
canonical | apport | 2.20.11-0ubuntu24 |
canonical | apport | 2.20.11-0ubuntu25 |
canonical | apport | 2.20.11-0ubuntu26 |
canonical | apport | 2.20.11-0ubuntu27 |
canonical | apport | 2.20.11-0ubuntu27.2 |
canonical | apport | 2.20.11-0ubuntu27.3 |
canonical | apport | 2.20.11-0ubuntu27.4 |
canonical | apport | 2.20.11-0ubuntu27.5 |
canonical | apport | 2.20.7-0ubuntu3 |
canonical | apport | 2.20.7-0ubuntu3.1 |
canonical | apport | 2.20.7-0ubuntu4 |
canonical | apport | 2.20.8-0ubuntu1 |
canonical | apport | 2.20.8-0ubuntu2 |
canonical | apport | 2.20.8-0ubuntu3 |
canonical | apport | 2.20.8-0ubuntu4 |
canonical | apport | 2.20.8-0ubuntu5 |
canonical | apport | 2.20.8-0ubuntu6 |
canonical | apport | 2.20.8-0ubuntu7 |
canonical | apport | 2.20.8-0ubuntu8 |
canonical | apport | 2.20.8-0ubuntu9 |
canonical | apport | 2.20.8-0ubuntu10 |
canonical | apport | 2.20.9-0ubuntu1 |
canonical | apport | 2.20.9-0ubuntu2 |
canonical | apport | 2.20.9-0ubuntu3 |
canonical | apport | 2.20.9-0ubuntu4 |
canonical | apport | 2.20.9-0ubuntu5 |
canonical | apport | 2.20.9-0ubuntu6 |
canonical | apport | 2.20.9-0ubuntu7 |
canonical | apport | 2.20.9-0ubuntu7.1 |
canonical | apport | 2.20.9-0ubuntu7.2 |
canonical | apport | 2.20.9-0ubuntu7.3 |
canonical | apport | 2.20.9-0ubuntu7.4 |
canonical | apport | 2.20.9-0ubuntu7.5 |
canonical | apport | 2.20.9-0ubuntu7.6 |
canonical | apport | 2.20.9-0ubuntu7.7 |
canonical | apport | 2.20.9-0ubuntu7.8 |
canonical | apport | 2.20.9-0ubuntu7.9 |
canonical | apport | 2.20.9-0ubuntu7.10 |
canonical | apport | 2.20.9-0ubuntu7.11 |
canonical | apport | 2.20.9-0ubuntu7.12 |
canonical | apport | 2.20.9-0ubuntu7.13 |
canonical | apport | 2.20.9-0ubuntu7.14 |
canonical | apport | 2.20.9-0ubuntu7.15 |
canonical | apport | 2.19.1-0ubuntu3 |
canonical | apport | 2.19.2-0ubuntu1 |
canonical | apport | 2.19.2-0ubuntu2 |
canonical | apport | 2.19.2-0ubuntu3 |
canonical | apport | 2.19.2-0ubuntu4 |
canonical | apport | 2.19.2-0ubuntu5 |
canonical | apport | 2.19.2-0ubuntu6 |
canonical | apport | 2.19.2-0ubuntu7 |
canonical | apport | 2.19.2-0ubuntu8 |
canonical | apport | 2.19.2-0ubuntu9 |
canonical | apport | 2.19.3-0ubuntu1 |
canonical | apport | 2.19.3-0ubuntu2 |
canonical | apport | 2.19.3-0ubuntu3 |
canonical | apport | 2.19.4-0ubuntu1 |
canonical | apport | 2.19.4-0ubuntu2 |
canonical | apport | 2.20-0ubuntu1 |
canonical | apport | 2.20-0ubuntu2 |
canonical | apport | 2.20-0ubuntu3 |
canonical | apport | 2.20.1-0ubuntu1 |
canonical | apport | 2.20.1-0ubuntu2 |
canonical | apport | 2.20.1-0ubuntu2.1 |
canonical | apport | 2.20.1-0ubuntu2.2 |
canonical | apport | 2.20.1-0ubuntu2.4 |
canonical | apport | 2.20.1-0ubuntu2.5 |
canonical | apport | 2.20.1-0ubuntu2.6 |
canonical | apport | 2.20.1-0ubuntu2.7 |
canonical | apport | 2.20.1-0ubuntu2.8 |
canonical | apport | 2.20.1-0ubuntu2.9 |
canonical | apport | 2.20.1-0ubuntu2.10 |
canonical | apport | 2.20.1-0ubuntu2.12 |
canonical | apport | 2.20.1-0ubuntu2.13 |
canonical | apport | 2.20.1-0ubuntu2.14 |
canonical | apport | 2.20.1-0ubuntu2.15 |
canonical | apport | 2.20.1-0ubuntu2.16 |
canonical | apport | 2.20.1-0ubuntu2.17 |
canonical | apport | 2.20.1-0ubuntu2.18 |
canonical | apport | 2.20.1-0ubuntu2.19 |
canonical | apport | 2.20.1-0ubuntu2.20 |
canonical | apport | 2.20.1-0ubuntu2.21 |
canonical | apport | 2.20.1-0ubuntu2.22 |
canonical | apport | 2.20.1-0ubuntu2.23 |
canonical | ubuntu_linux | 14.04 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References