CVE-2019-11485 describes a vulnerability in Apport, affecting Apport and Ubuntu Linux, where a world-writable lock file could be manipulated to prevent crash handling. This local vulnerability has a low severity CVSS score of 3.3, indicating that an attacker with local access could achieve a denial of service by hindering crash reporting. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low likelihood of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.14.1, < 2.14.1-0ubuntu3.29+esm2CPE match | cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* | ||
>= 2.20.1, < 2.20.1-0ubuntu2.20CPE match | cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* | ||
>= 2.20.11, < 2.20.11-0ubuntu8.1CPE match | cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* | ||
>= 2.20.9, < 2.20.9-0ubuntu7.8CPE match | cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:apport_project:apport:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.