It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1917904 | Vendor Advisory Exploit |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-06-11 21:15
Updated : 2021-06-23 11:49
NVD link : CVE-2021-32557
Mitre link : CVE-2021-32557
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
canonical
- apport