========================================================================== Ubuntu Security Notice USN-3664-1 May 30, 2018 apport vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 17.10 - Ubuntu 16.04 LTS Summary: Apport could be tricked into causing a denial of service or escalate privileges. Software Description: - apport: automatically generate crash reports for debugging Details: Sander Bos discovered that Apport incorrectly handled core dumps when certain files are missing from /proc. A local attacker could possibly use this issue to cause a denial of service, gain root privileges, or escape from containers. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: apport 2.20.9-0ubuntu7.1 Ubuntu 17.10: apport 2.20.7-0ubuntu3.9 Ubuntu 16.04 LTS: apport 2.20.1-0ubuntu2.18 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/usn/usn-3664-1 CVE-2018-6552 Package Information: https://launchpad.net/ubuntu/+source/apport/2.20.9-0ubuntu7.1 https://launchpad.net/ubuntu/+source/apport/2.20.7-0ubuntu3.9 https://launchpad.net/ubuntu/+source/apport/2.20.1-0ubuntu2.18