CVE-2009-1295 Details

CVE-2009-1295

Published: 2009-04-30
Last Modified: 2009-05-15
CVE Author: NIST National Vulnerability Database
CVE Assigner: cve@mitre.org
Summary

Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.

Analysis
Common Vulnerability Score System v2.0
Severity Low
Base Score 1.9/10
Exploit Score 3.4/10
Access Vector Local
Access Complexity Medium
Authentication None
Impact Score 2.9/10
Confidentiality Impact None
Availability Impact None
Integrity Impact Partial
Vector String AV:L/AC:M/Au:N/C:N/I:P/A:N
Common Vulnerability Score System v3.1

NIST has not assigned a CVSSv3.1 Score.

Products Reported
CPE Vulnerable Start Excluding
cpe:2.3:a:apport:apport:*:*:*:*:*:*:*:* Yes - -
cpe:2.3:o:ubuntu:ubuntu:8.0.4_lts:*:*:*:*:*:*:* Yes - -
cpe:2.3:o:ubuntu:ubuntu:8.1.0:*:*:*:*:*:*:* Yes - -
cpe:2.3:o:ubuntu:ubuntu:9.0.4:*:*:*:*:*:*:* Yes - -
References

http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://secunia.com/advisories/34947
http://secunia.com/advisories/34952
http://secunia.com/advisories/35065
http://www.securityfocus.com/bid/34776
http://www.ubuntu.com/usn/usn-768-1
https://bugs.launchpad.net/bugs/357024
https://launchpad.net/bugs/cve/2009-1295

CVE ID
CVE-2009-1295
Published
2009-04-30
Modified
2009-05-15
CVSSv2.0
Low
PCI Compliance
Pass
US-CERT Alert
No
CWE
CWE-16

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities.