CVE-2009-1295

Publication date 30 April 2009

Last updated 24 July 2024


Ubuntu priority

Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.

Read the notes from the security team

Status

Package Ubuntu Release Status
apport 9.04 jaunty
Fixed 1.0-0ubuntu5.2
8.10 intrepid
Fixed 0.119.2
8.04 LTS hardy
Fixed 0.108.4
6.06 LTS dapper Not in release

Notes


jdstrand

bug mentions fuse being an attack vector, but it isn't on Jaunty symlink/race condition

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
apport

References

Related Ubuntu Security Notices (USN)

    • USN-768-1
    • Apport vulnerability
    • 29 April 2009

Other references