Vulnerability Description
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Apport | >= 2.14.1-0ubuntu3, < 2.14.1-0ubuntu3.29\+esm7 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1917904Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1917904Vendor Advisory
FAQ
What is CVE-2021-32556?
CVE-2021-32556 is a vulnerability with a CVSS score of 3.8 (LOW). It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
How severe is CVE-2021-32556?
CVE-2021-32556 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32556?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Apport.