Users need to upgrade the OS as soon as possible

May 25, 2015 15:52 GMT  ·  By

A couple of Apport vulnerabilities have been found and fixed in Ubuntu 15.04, Ubuntu 14.10, Ubuntu 14.04 LTS, and Ubuntu 12.04 LTS.

Apport is the component used to automatically generate crash reports for debugging, so it's not exactly the first thing you would consider to be exposed. From the looks of it, Apport could have been tricked into creating arbitrary files as an administrator, which would result in a privilege escalation.

"Sander Bos discovered that Apport incorrectly handled permissions when the system was configured to generate core dumps for setuid binaries. A local attacker could use this issue to gain elevated privileges. Also, Philip Pettersson discovered that Apport contained race conditions resulting core dumps to be generated with incorrect permissions in arbitrary locations. A local attacker could use this issue to gain elevated privileges," reads the security notice.

More details about the Apport exploits can be found in the official security notice. Users have been advised to upgrade their system as soon as possible. That can be done in a couple of ways, either with the Software Update or from the terminal. In any case, users won't have to reboot their system in order to complete the process. The procedure is the same for all the supported Ubuntu OSes.