Vulnerability Description
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Apport | < 2.19.2 |
Related Weaknesses (CWE)
References
- https://launchpad.net/apport/trunk/2.19.2Third Party Advisory
- https://usn.ubuntu.com/2782-1/Third Party Advisory
- https://launchpad.net/apport/trunk/2.19.2Third Party Advisory
- https://usn.ubuntu.com/2782-1/Third Party Advisory
FAQ
What is CVE-2015-1341?
CVE-2015-1341 is a vulnerability with a CVSS score of 7.4 (HIGH). Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.
How severe is CVE-2015-1341?
CVE-2015-1341 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1341?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Canonical Apport.