Beveiligingsadvies

CVE-2021-32550

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-06-12 03:40:38
Laatst bijgewerkt 2024-09-16 23:22:01
Toegewezen door canonical
CVSS-score 7.3
Status PUBLISHED

Beschrijving

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.