Vulnerability Database

314,343

Total vulnerabilities in the database

CVE-2025-5467

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

  • Published: Dec 10, 2025
  • Updated: Dec 18, 2025
  • CVE: CVE-2025-5467
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.3
  • AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CWEs:

Software From Fixed in
canonical / apport 2.20.1-0ubuntu1 2.20.1-0ubuntu2.30
canonical / apport 2.20.9-0ubuntu7 2.20.9-0ubuntu7.29
canonical / apport 2.20.11-0ubuntu27 2.20.11-0ubuntu27.28
canonical / apport 2.20.11-0ubuntu82 2.20.11-0ubuntu82.7
canonical / apport 2.28.1-0ubuntu1 2.28.1-0ubuntu3.6
canonical / apport 2.32.0-0ubuntu1 2.32.0-0ubuntu5.1