CVE detail
CVE-2019-11485
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- Ubuntu apport TOCTOU security vulnerability (CVE-2019-7307)GitHub Security Lab
This is the second post in our series about Ubuntu’s crash reporting system. We’ll review CVE-2019-7307, a TOCTOU vulnerability that enables a local attacker to include the contents of any file on the system in a crash report.
vendorgithub.blogDec 17, 2019, 5:19 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-28658CVSS 5.5 · Medium
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
- CVE-2022-28657CVSS 7.8 · High
Apport does not disable python crash handler before entering chroot
- CVE-2022-28656CVSS 5.5 · Medium
is_closing_session() allows users to consume RAM in the Apport process
- CVE-2022-28655CVSS 7.1 · High
is_closing_session() allows users to create arbitrary tcp dbus connections
- CVE-2022-28654CVSS 5.5 · Medium
is_closing_session() allows users to fill up apport.log
- CVE-2022-28652CVSS 5.5 · Medium
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack