vendor:
Apport
by:
Anonymous
6,5
CVSS
MEDIUM
Code Injection and Path Traversal
94, 22
CWE
Product Name: Apport
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2016-9949, CVE-2016-9950, CVE-2016-9951
CPE: apport
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9949/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9950/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-9951/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9951/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2016
CrashDB Code Injection and Path Traversal Bugs in Apport
Two issues were reported to the Apport maintainers, a CrashDB code injection issue tracked with CVE-2016-9949 and a path traversal bug tracked with CVE-2016-9950. An additional problem where arbitrary commands can be called with the “Relaunch” action is tracked by CVE-2016-9951.
Mitigation:
The fix was released on 2016-12-14.