CVE-2021-25683

It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
canonicalCNA
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
VendorProductVersion
canonicalapport
2.20.1-0ubuntu1 ≤
𝑥
< 2.20.1-0ubuntu2.30
canonicalapport
2.20.9-0ubuntu1 ≤
𝑥
< 2.20.9-0ubuntu7.23
canonicalapport
2.20.11-0ubuntu27 ≤
𝑥
< 2.20.11-0ubuntu27.16
canonicalapport
2.20.11-0ubuntu50 ≤
𝑥
< 2.20.11-0ubuntu50.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apport
groovy
Fixed 2.20.11-0ubuntu50.5
released
focal
Fixed 2.20.11-0ubuntu27.16
released
bionic
Fixed 2.20.9-0ubuntu7.23
released
xenial
Fixed 2.20.1-0ubuntu2.30
released
trusty
Fixed 2.14.1-0ubuntu3.29+esm6
released