Vulnerability Details CVE-2017-10708
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2017-10708
-
cpe:2.3:a:apport_project:apport:-
-
cpe:2.3:a:apport_project:apport:0.13
-
cpe:2.3:a:apport_project:apport:1.10
-
cpe:2.3:a:apport_project:apport:1.10.1
-
cpe:2.3:a:apport_project:apport:1.11
-
cpe:2.3:a:apport_project:apport:1.12
-
cpe:2.3:a:apport_project:apport:1.12.1
-
cpe:2.3:a:apport_project:apport:1.13.1
-
cpe:2.3:a:apport_project:apport:1.13.2
-
cpe:2.3:a:apport_project:apport:1.13.3
-
cpe:2.3:a:apport_project:apport:1.14
-
cpe:2.3:a:apport_project:apport:1.15
-
cpe:2.3:a:apport_project:apport:1.16
-
cpe:2.3:a:apport_project:apport:1.17
-
cpe:2.3:a:apport_project:apport:1.17.1
-
cpe:2.3:a:apport_project:apport:1.17.2
-
cpe:2.3:a:apport_project:apport:1.18
-
cpe:2.3:a:apport_project:apport:1.20.1
-
cpe:2.3:a:apport_project:apport:1.21
-
cpe:2.3:a:apport_project:apport:1.21.1
-
cpe:2.3:a:apport_project:apport:1.21.2
-
cpe:2.3:a:apport_project:apport:1.21.3
-
cpe:2.3:a:apport_project:apport:1.22
-
cpe:2.3:a:apport_project:apport:1.22.1
-
cpe:2.3:a:apport_project:apport:1.23
-
cpe:2.3:a:apport_project:apport:1.23.1
-
cpe:2.3:a:apport_project:apport:1.24
-
cpe:2.3:a:apport_project:apport:1.25
-
cpe:2.3:a:apport_project:apport:1.26
-
cpe:2.3:a:apport_project:apport:1.9.4
-
cpe:2.3:a:apport_project:apport:1.9.5
-
cpe:2.3:a:apport_project:apport:1.9.6
-
cpe:2.3:a:apport_project:apport:1.90
-
cpe:2.3:a:apport_project:apport:1.91
-
cpe:2.3:a:apport_project:apport:1.92
-
cpe:2.3:a:apport_project:apport:1.93
-
cpe:2.3:a:apport_project:apport:1.94
-
cpe:2.3:a:apport_project:apport:1.94.1
-
cpe:2.3:a:apport_project:apport:1.95
-
cpe:2.3:a:apport_project:apport:2.0
-
cpe:2.3:a:apport_project:apport:2.0.1
-
cpe:2.3:a:apport_project:apport:2.1
-
cpe:2.3:a:apport_project:apport:2.1.1
-
cpe:2.3:a:apport_project:apport:2.10
-
cpe:2.3:a:apport_project:apport:2.10.1
-
cpe:2.3:a:apport_project:apport:2.10.2
-
cpe:2.3:a:apport_project:apport:2.11
-
cpe:2.3:a:apport_project:apport:2.12
-
cpe:2.3:a:apport_project:apport:2.12.1
-
cpe:2.3:a:apport_project:apport:2.12.2
-
cpe:2.3:a:apport_project:apport:2.12.3
-
cpe:2.3:a:apport_project:apport:2.12.4
-
cpe:2.3:a:apport_project:apport:2.12.5
-
cpe:2.3:a:apport_project:apport:2.12.6
-
cpe:2.3:a:apport_project:apport:2.12.7
-
cpe:2.3:a:apport_project:apport:2.13
-
cpe:2.3:a:apport_project:apport:2.13.1
-
cpe:2.3:a:apport_project:apport:2.13.2
-
cpe:2.3:a:apport_project:apport:2.13.3
-
cpe:2.3:a:apport_project:apport:2.14
-
cpe:2.3:a:apport_project:apport:2.14.1
-
cpe:2.3:a:apport_project:apport:2.14.2
-
cpe:2.3:a:apport_project:apport:2.14.3
-
cpe:2.3:a:apport_project:apport:2.14.4
-
cpe:2.3:a:apport_project:apport:2.14.5
-
cpe:2.3:a:apport_project:apport:2.14.6
-
cpe:2.3:a:apport_project:apport:2.14.7
-
cpe:2.3:a:apport_project:apport:2.15
-
cpe:2.3:a:apport_project:apport:2.15.1
-
cpe:2.3:a:apport_project:apport:2.16
-
cpe:2.3:a:apport_project:apport:2.16.1
-
cpe:2.3:a:apport_project:apport:2.16.2
-
cpe:2.3:a:apport_project:apport:2.17
-
cpe:2.3:a:apport_project:apport:2.17.1
-
cpe:2.3:a:apport_project:apport:2.17.2
-
cpe:2.3:a:apport_project:apport:2.17.3
-
cpe:2.3:a:apport_project:apport:2.18
-
cpe:2.3:a:apport_project:apport:2.18.1
-
cpe:2.3:a:apport_project:apport:2.19
-
cpe:2.3:a:apport_project:apport:2.19.1
-
cpe:2.3:a:apport_project:apport:2.19.2
-
cpe:2.3:a:apport_project:apport:2.19.3
-
cpe:2.3:a:apport_project:apport:2.19.4
-
cpe:2.3:a:apport_project:apport:2.2
-
cpe:2.3:a:apport_project:apport:2.2.1
-
cpe:2.3:a:apport_project:apport:2.2.2
-
cpe:2.3:a:apport_project:apport:2.2.3
-
cpe:2.3:a:apport_project:apport:2.2.4
-
cpe:2.3:a:apport_project:apport:2.2.5
-
cpe:2.3:a:apport_project:apport:2.20
-
cpe:2.3:a:apport_project:apport:2.20.1
-
cpe:2.3:a:apport_project:apport:2.20.2
-
cpe:2.3:a:apport_project:apport:2.20.3
-
cpe:2.3:a:apport_project:apport:2.20.4
-
cpe:2.3:a:apport_project:apport:2.20.6
-
cpe:2.3:a:apport_project:apport:2.3
-
cpe:2.3:a:apport_project:apport:2.4
-
cpe:2.3:a:apport_project:apport:2.5
-
cpe:2.3:a:apport_project:apport:2.5.1
-
cpe:2.3:a:apport_project:apport:2.5.2
-
cpe:2.3:a:apport_project:apport:2.5.3
-
cpe:2.3:a:apport_project:apport:2.6
-
cpe:2.3:a:apport_project:apport:2.6.1
-
cpe:2.3:a:apport_project:apport:2.6.2
-
cpe:2.3:a:apport_project:apport:2.6.3
-
cpe:2.3:a:apport_project:apport:2.7
-
cpe:2.3:a:apport_project:apport:2.8
-
cpe:2.3:a:apport_project:apport:2.9
-
cpe:2.3:a:apport_project:apport:2.9.1
-
cpe:2.3:a:apport_project:apport:2.9.2