USN-2007-1: Apport vulnerability
24 October 2013
Apport could be made to expose privileged information.
Releases
Packages
- apport - automatically generate crash reports for debugging
Details
Martin Carpenter discovered that Apport set incorrect permissions on core
dump files generated by setuid binaries. A local attacker could possibly
use this issue to obtain privileged information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 13.10
Ubuntu 13.04
Ubuntu 12.10
Ubuntu 12.04
In general, a standard system update will make all the necessary changes.