LWN.net Logo

apport: AppArmor policy is too lenient

Package(s):apport CVE #(s):
Created:December 18, 2012 Updated:December 19, 2012
Description: From the Ubuntu advisory:

Dan Rosenberg discovered that an application running under an AppArmor profile that allowed unconfined execution of apport-bug could escape confinement by calling apport-bug with a crafted environment. While not a vulnerability in apport itself, this update mitigates the issue by sanitizing certain variables in the apport-bug shell script.

Alerts:
Ubuntu USN-1668-1 2012-12-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds