Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1326
HistoryApr 13, 2023 - 12:00 a.m.

CVE-2023-1326

2023-04-1300:00:00
ubuntu.com
ubuntu.com
473
privilege escalation
apport-cli
sudo
pager
local attacker
exploit
system administrator
ubuntu

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.2%

A privilege escalation attack was found in apport-cli 2.26.0 and earlier
which is similar to CVE-2023-26604. If a system is specially configured to
allow unprivileged users to run sudo apport-cli, less is configured as the
pager, and the terminal size can be set: a local attacker can escalate
privilege. It is extremely unlikely that a system administrator would
configure sudo to allow unprivileged users to perform this class of
exploit.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchapport< 2.20.9-0ubuntu7.29UNKNOWN
ubuntu20.04noarchapport< 2.20.11-0ubuntu27.26UNKNOWN
ubuntu22.04noarchapport< 2.20.11-0ubuntu82.4UNKNOWN
ubuntu22.10noarchapport< 2.23.1-0ubuntu3.2UNKNOWN
ubuntu23.04noarchapport< 2.26.1-0ubuntu2UNKNOWN

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.2%