It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
History

Thu, 11 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical apport
Canonical ubuntu
Vendors & Products Canonical
Canonical apport
Canonical ubuntu

Wed, 10 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Description It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
Title Ubuntu Apport Insecure File Permissions Vulnerability
Weaknesses CWE-708
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2025-12-10T18:00:35.967Z

Updated: 2025-12-10T18:45:08.960Z

Reserved: 2025-06-02T12:03:56.269Z

Link: CVE-2025-5467

cve-icon Vulnrichment

Updated: 2025-12-10T18:45:05.126Z

cve-icon NVD

Status : Received

Published: 2025-12-10T18:16:19.070

Modified: 2025-12-10T18:16:19.070

Link: CVE-2025-5467

cve-icon Redhat

No data.