PublicDateAtUSN: 2017-07-18 18:00:00 UTC Candidate: CVE-2017-10708 CRD: 2017-07-18 18:00:00 UTC PublicDate: 2017-07-18 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10708 https://ubuntu.com/security/notices/USN-3354-1 Description: An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file. Ubuntu-Description: Notes: tyhicks> Apport registers itself as the default handler for .crash files so an attacker could trick a user into opening a malicious .crash file and execute arbitrary code as the user. tyhicks> A potential method of hardening apport against these types of attacks is to unregister it as the handler for .crash files. Bugs: https://launchpad.net/bugs/1700573 Priority: medium Discovered-by: Felix Wilhelm Assigned-to: leosilva CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_apport: upstream: https://bazaar.launchpad.net/~apport-hackers/apport/trunk/revision/3153 upstream_apport: released (2.20.6) precise/esm_apport: DNE trusty_apport: released (2.14.1-0ubuntu3.25) trusty/esm_apport: released (2.14.1-0ubuntu3.25) vivid/ubuntu-core_apport: DNE xenial_apport: released (2.20.1-0ubuntu2.10) esm-infra/xenial_apport: released (2.20.1-0ubuntu2.10) yakkety_apport: released (2.20.3-0ubuntu8.7) zesty_apport: released (2.20.4-0ubuntu4.5) devel_apport: not-affected (2.20.6-0ubuntu4)