Bugzilla – Bug 1210451
VUL-0: CVE-2023-1326: apport,apport-crashdb-sle: privilege escalation via apport-cli if sudo is allowed
Last modified: 2023-07-03 16:14:04 UTC
CVE-2023-1326 A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1326 https://www.cve.org/CVERecord?id=CVE-2023-1326 http://www.cvedetails.com/cve/CVE-2023-1326/ https://github.com/canonical/apport/commit/e5f78cc89f1f5888b6a56b785dddcb0364c48ecb