CVE-2018-6552 describes a vulnerability in Apport, affecting versions 2.20.8-0ubuntu4 through 2.20.9-0ubuntu7 and others, where improper handling of crashes from PID namespaces allows local users to create root-owned files. This flaw, rated High severity (CVSS 7.8), could lead to denial of service, potential root privilege escalation, or container escapes due to incorrect PID handling in the global namespace. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.14.1CPE matchmatch criteria | cpe:2.3:a:apport_project:apport:2.14.1:*:*:*:*:*:*:* | ||
2.20.9CPE matchmatch criteria | cpe:2.3:a:apport_project:apport:2.20.9:*:*:*:*:*:*:* | ||
2.20.7CPE matchmatch criteria | cpe:2.3:a:apport_project:apport:2.20.7:*:*:*:*:*:*:* | ||
2.20.1CPE matchmatch criteria | cpe:2.3:a:apport_project:apport:2.20.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.