Oval Definition:oval:com.ubuntu.xenial:def:201699490000000
Revision Date:2016-12-17Version:1
Title:CVE-2016-9949 on Ubuntu 16.04 LTS (xenial) - medium.
Description:An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code. Donncha O Cearbhaill discovered that the crash file parser in Apport improperly treated the CrashDB field as python code. An attacker could use this to convince a user to open a maliciously crafted crash file and execute arbitrary code with the privileges of that user.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-9949
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND apport package in xenial was vulnerable but has been fixed (note: '2.20.1-0ubuntu2.4').
  • BACK