Package: apport
Version: 2.20.4-5
Tags: security

Apport tries to create /var/crash/.lock if doesn't exist already. But /var/crash/ is world-writable, so a malicious local user could do:

  ln -sf /nonexistent /var/crash/.lock

to prevent Apport from creating the lock file.

--
Jakub Wilk

Reply via email to