Vulnerability Description
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Apport | <= 2.26.0 |
| Canonical | Ubuntu Linux | 18.04 |
Related Weaknesses (CWE)
References
- https://github.com/canonical/apport/commit/e5f78cc89f1f5888b6a56b785dddcb0364c48Patch
- https://ubuntu.com/security/notices/USN-6018-1Vendor Advisory
- https://github.com/canonical/apport/commit/e5f78cc89f1f5888b6a56b785dddcb0364c48Patch
- https://ubuntu.com/security/notices/USN-6018-1Vendor Advisory
FAQ
What is CVE-2023-1326?
CVE-2023-1326 is a vulnerability with a CVSS score of 7.7 (HIGH). A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, les...
How severe is CVE-2023-1326?
CVE-2023-1326 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1326?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Apport, Canonical Ubuntu Linux.