CVE-2019-11481 - CERT CVE
ID CVE-2019-11481
Sažetak Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
Reference
CVSS
Base: 6.1
Impact: 8.5
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE PARTIAL PARTIAL
CVSS vektor AV:L/AC:L/Au:N/C:C/I:P/A:P
Zadnje važnije ažuriranje 12-06-2023 - 07:15
Objavljeno 08-02-2020 - 05:15