CVE-2009-1295
Severity CVSS v4.0:
Pending analysis
Type:
CWE-16
Configuration Errors
Publication date:
30/04/2009
Last modified:
09/04/2025
Description
Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.
Impact
Base Score 2.0
1.90
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apport:apport:*:*:*:*:*:*:*:* | 0.1.0.8.1 (including) | |
cpe:2.3:o:ubuntu:ubuntu:8.0.4_lts:*:*:*:*:*:*:* | ||
cpe:2.3:o:ubuntu:ubuntu:8.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:ubuntu:ubuntu:9.0.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://secunia.com/advisories/34947
- http://secunia.com/advisories/34952
- http://secunia.com/advisories/35065
- http://www.securityfocus.com/bid/34776
- http://www.ubuntu.com/usn/usn-768-1
- https://bugs.launchpad.net/bugs/357024
- https://launchpad.net/bugs/cve/2009-1295
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://secunia.com/advisories/34947
- http://secunia.com/advisories/34952
- http://secunia.com/advisories/35065
- http://www.securityfocus.com/bid/34776
- http://www.ubuntu.com/usn/usn-768-1
- https://bugs.launchpad.net/bugs/357024
- https://launchpad.net/bugs/cve/2009-1295