CVE-2025-5467 - CVE House
Back to Database
Status published Low CVE-2025-5467

Ubuntu Apport Insecure File Permissions Vulnerability

Vulnerability Description

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5467

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Rich Mirch

Affected Vendor

Affected Software

apport
Vulnerable Versions:
2.20.11-0ubuntu82, 2.32.0, 2.20.9, 2.28.1, 2.33.0, 2.20.1, 2.20.11-0ubuntu27

Timeline

Official Publish: December 10th, 2025
Last Modified: December 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.