CVE-2021-32554

Description

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.061

Associated Vulnerability

VulnerabilityOS Platform
automatically generate crash reports for debugging (USN-4965-1) apport_2.20.9-0ubuntu7.24_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) apport_2.20.11-0ubuntu50.7_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) apport_2.20.11-0ubuntu65.1_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) apport_2.20.11-0ubuntu27.18_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) python-apport_2.20.9-0ubuntu7.24_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) python3-apport_2.20.9-0ubuntu7.24_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) python3-apport_2.20.11-0ubuntu50.7_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) python3-apport_2.20.11-0ubuntu65.1_all.debLinux
automatically generate crash reports for debugging (USN-4965-1) python3-apport_2.20.11-0ubuntu27.18_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234