CVE-2018-6552
Published: May 31, 2018
Modified: Sep 17, 2024
Description
Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The is_same_ns() function returns True when /proc/<global pid>/ does not exist in order to indicate that the crash should be handled in the global namespace rather than inside of a container. However, the portion of the data/apport code that decides whether or not to forward a crash to a container does not always replace sys.argv[1] with the value stored in the host_pid variable when /proc/<global pid>/ does not exist which results in the container pid being used in the global namespace. This flaw affects versions 2.20.8-0ubuntu4 through 2.20.9-0ubuntu7, 2.20.7-0ubuntu3.7, 2.20.7-0ubuntu3.8, 2.20.1-0ubuntu2.15 through 2.20.1-0ubuntu2.17, and 2.14.1-0ubuntu3.28.
| Vendor | Product | Versions |
|---|---|---|
n/a | Apport | affected 2.20.8-0ubuntu4 - < unspecifiedaffected unspecified - < 2.20.9-0ubuntu7.1 |
n/a | Apport | affected 2.20.1-0ubuntu2.15 - < unspecifiedaffected unspecified - < 2.20.1-0ubuntu2.18 |
n/a | Apport | affected 2.20.7-0ubuntu3.7 - < unspecifiedaffected unspecified - < 2.20.7-0ubuntu3.9 |
n/a | Apport | affected 2.14.1-0ubuntu3.28 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now