CVE-2019-11481: Apport Project Apport

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.

Affected products

  • Apport Project Apport: affected versions not specified
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only

Published 2020-02-08. Last modified 2026-06-17.