CVE-2009-1295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
30/04/2009
Last modified:
09/04/2025

Description

Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apport:apport:*:*:*:*:*:*:*:* 0.1.0.8.1 (including)
cpe:2.3:o:ubuntu:ubuntu:8.0.4_lts:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu:8.1.0:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu:9.0.4:*:*:*:*:*:*:*