CVE-2019-11481: Apport Project Apport
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
Affected products
- Apport Project Apport: affected versions not specified
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
Published 2020-02-08. Last modified 2026-06-17.