Back to Database
Status published
High
CVE-2015-1338
kernel_crashdump in Apport before 2.19 allows local users to cause...
Vulnerability Description
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-1338
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.ubuntu.com/usn/USN-2744-1
- https://launchpad.net/apport/trunk/2.19
- https://www.exploit-db.com/exploits/38353/
- https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1492570
- http://www.halfdog.net/Security/2015/ApportKernelCrashdumpFileAccessVulnerabilities/
- http://seclists.org/fulldisclosure/2015/Sep/101
- http://packetstormsecurity.com/files/133723/Ubuntu-Apport-kernel_crashdump-Symlink.html
More from apport project
View All →CVE-2017-10708
An issue was discovered in Apport through 2.20.x. In apport/report.py,...
High
7.8
CVE-2016-9951
An issue was discovered in Apport before 2.20.4. A malicious...
Medium
6.5
CVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is...
High
7.8
CVE-2016-9949
An issue was discovered in Apport before 2.20.4. In apport/ui.py,...
High
7.8
CVE-2015-1318
The crash reporting feature in Apport 2.13 through 2.17.x before...
High
7.2
Affected Vendor
apport project
View all reports →Affected Software
apport, ubuntu linux
Vulnerable Versions:
0, 12.04, 14.04, 15.04
Timeline
Official Publish:
October 1st, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.