SB2018060606 - Privilege escalation in Ubuntu apport



SB2018060606 - Privilege escalation in Ubuntu apport

Published: June 6, 2018

Security Bulletin ID SB2018060606
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2018-6552)

The vulnerability allows a local attacker to gain elevated privileges or cause DoS condition on the target system.

The vulnerability exists in the apport package used in multiple releases of Ubuntu due to improper handling of core dumps by the affected software when certain files are missing from the /proc directory. A local attacker can send remove certain files from the /proc directory to gain root privileges, deploy malicious code that escapes containers, or cause the service to crash.


Remediation

Install update from vendor's website.