Vulnerability Description
It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Apport | >= 2.20.1-0ubuntu1, < 2.20.1-0ubuntu2.30 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/apport/+bug/2106338ExploitThird Party Advisory
- https://www.stratascale.com/resource/cve-2025-32462-ubuntu-apport-vulnerability/ExploitThird Party Advisory
FAQ
What is CVE-2025-5467?
CVE-2025-5467 is a vulnerability with a CVSS score of 3.3 (LOW). It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expec...
How severe is CVE-2025-5467?
CVE-2025-5467 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5467?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Apport.