CVE-2019-7307 - CVE House
Back to Database
Status published Medium CVE-2019-7307

Apport contains a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml

Vulnerability Description

Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allows a local attacker to replace this file with a symlink to any other file on the system and so cause Apport to include the contents of this other file in the resulting crash report. The crash report could then be read by that user either by causing it to be uploaded and reported to Launchpad, or by leveraging some other vulnerability to read the resulting crash report, and so allow the user to read arbitrary files on the system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-7307

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Kevin Backhouse of Semmle Security Research Team

Affected Vendor

Affected Software

apport
Vulnerable Versions:
before 2.14.1-0ubuntu3.29+esm1, before 2.20.1-0ubuntu2.19, before 2.20.9-0ubuntu7.7, before 2.20.10-0ubuntu27.1, before 2.20.11-0ubuntu5

Timeline

Official Publish: August 29th, 2019
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Weaknesses (CWE)