CVE-2017-14177: Apport Project Apport
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.
Affected products
- Apport Project Apport: up to and including 2.20.7
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only; version 17.10 only; version 18.04 only
Published 2018-02-02. Last modified 2026-06-17.