|
|
Log in / Subscribe / Register

Ubuntu alert USN-7545-1 (apport)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7545-1] Apport vulnerability
Date:  Fri, 30 May 2025 12:51:18 +0000
Message-ID:  <E1uKzCg-0005KS-S8@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7545-1 May 29, 2025 apport vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Apport could be made to leak sensitive information. Software Description: - apport: automatically generate crash reports for debugging Details: Qualys discovered that Apport incorrectly handled metadata when processing application crashes. An attacker could possibly use this issue to leak sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 apport 2.32.0-0ubuntu5.1 python3-apport 2.32.0-0ubuntu5.1 Ubuntu 24.10 apport 2.30.0-0ubuntu4.3 python3-apport 2.30.0-0ubuntu4.3 Ubuntu 24.04 LTS apport 2.28.1-0ubuntu3.6 python3-apport 2.28.1-0ubuntu3.6 Ubuntu 22.04 LTS apport 2.20.11-0ubuntu82.7 python3-apport 2.20.11-0ubuntu82.7 Ubuntu 20.04 LTS apport 2.20.11-0ubuntu27.28 python3-apport 2.20.11-0ubuntu27.28 Ubuntu 18.04 LTS apport 2.20.9-0ubuntu7.29+esm1 Available with Ubuntu Pro python-apport 2.20.9-0ubuntu7.29+esm1 Available with Ubuntu Pro python3-apport 2.20.9-0ubuntu7.29+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS apport 2.20.1-0ubuntu2.30+esm5 Available with Ubuntu Pro python-apport 2.20.1-0ubuntu2.30+esm5 Available with Ubuntu Pro python3-apport 2.20.1-0ubuntu2.30+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7545-1 CVE-2025-5054 Package Information: https://launchpad.net/ubuntu/+source/apport/2.32.0-0ubunt... https://launchpad.net/ubuntu/+source/apport/2.30.0-0ubunt... https://launchpad.net/ubuntu/+source/apport/2.28.1-0ubunt... https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubun... https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubun...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmg4tnMACgkQcpJm3tlz hgEC7Q/8D44jnhdLj/3kBZZgYUFcbuA6msr9ZYox6AUiae1PlUHh7q6MJkmd+4EN VCCR9WfrX8hbqqRIpoDNOE680GSjVhDR/MYzhTUB2/K1VidplyH7kiX0YlmnYXzf hnVJow94vy7GFqf+8ly6UsHe4TglCAyaWqphsbxfe4EtyJx+uESsC4T1s/P4Ul2c ID4GEMnizvUu5A60Ens3pMDdRN9pkkQbNfRes4l25ZnSdgbWSFQVYy1oW5bnyo1q Be+Aw7ZDwn2JVymGEzajUQcnQl/WYH+eAD7ZnG+BgtDLdN7C8b84ou/NoEYYGmS+ /JOB8tc4E9/GsJR+O4Cti/E34zXWcARA9VU3/LeiCoay6zb1Bhy6uGEAzyDwUNuY mUUE549NLSXFTIbMyH/4B8F9+ZZHwbJdeD33NqiLKTaQDzVMTqnA+nDwnwK2w60e nuhRuSPIX+D0u3SeqIYAtq2JdNWGuGncNE7OYp08uIOmUJwlY+m17MGpqN3htM5o FsJDd+MsPqC8RijzarmkuyMf9dlr5aRIqnegbZIZVPPpOCzG7aN+DySfFjITCasP elFvpSjBqhzU3e1xUU5zigr0Gb7ox0ziQp8TL9CHqEKyz10vvgKTGQQcnrEbrNPq js8CM2HU3RkR3kX+Om6llNTdl/Yf4V3hrmQbaAUPVzGFme7XGy0= =w58O -----END PGP SIGNATURE-----


Attachment: None (type=text/plain)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds