7.8
CVSSv3

CVE-2017-10708

Published: 18/07/2017 Updated: 07/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Apport up to and including 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote malicious users to execute arbitrary code via a crafted .crash file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apport project apport

Vendor Advisories

An attacker could trick a user into opening a malicious crash file and execute arbitrary code as the user ...