Ubuntu whoopsie integer overflow vulnerability (CVE-2019-11484)

This is the fourth and final post in a series about Ubuntu’s crash reporting system. We’ll review CVE-2019-11484, a vulnerability in whoopsie which enables a local attacker to get a she...

By · · 1 min read
Ubuntu whoopsie integer overflow vulnerability (CVE-2019-11484)

Source: The GitHub Blog

This is the fourth and final post in a series about Ubuntu’s crash reporting system. We’ll review CVE-2019-11484, a vulnerability in whoopsie which enables a local attacker to get a shell as the whoopsie user, thereby gaining the ability to read any crash report.