Oval Definition:oval:com.ubuntu.trusty:def:20169949000
Revision Date:2016-12-16Version:1
Title:CVE-2016-9949 on Ubuntu 14.04 LTS (trusty) - medium.
Description:An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code. Donncha O Cearbhaill discovered that the crash file parser in Apport improperly treated the CrashDB field as python code. An attacker could use this to convince a user to open a maliciously crafted crash file and execute arbitrary code with the privileges of that user.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-9949
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND The 'apport' package in trusty was vulnerable but has been fixed (note: '2.14.1-0ubuntu3.23').
  • BACK