Vulnerability Name: | CVE-2017-14180 (CCN-138846) | ||||||||||||||||||||
Assigned: | 2017-10-23 | ||||||||||||||||||||
Published: | 2017-10-23 | ||||||||||||||||||||
Updated: | 2018-02-15 | ||||||||||||||||||||
Summary: | Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179. | ||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-400 | ||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-14180 Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bazaar.launchpad.net/~apport-hackers/apport/trunk/revision/3171 Source: CCN Type: Launchpad Bug #1726372 Multiple security issues in Apport Source: XF Type: UNKNOWN ubuntu-cve201714180-dos(138846) Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://launchpad.net/bugs/1726372 Source: CONFIRM Type: Third Party Advisory https://people.canonical.com/~ubuntu-security/cve/?cve=CVE-2017-14180 Source: UBUNTU Type: Third Party Advisory USN-3480-1 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |