CVE-2017-6507
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
Ha sido descubierto un problema en AppArmor en versiones anteriores a 2.12. El manejo incorrecto de perfiles AppArmor desconocidos en secuencias de comandos init de AppArmor, trabajos upstart, y/o archivos de unidad systemd permite a un atacante tener posiblemente superficies de ataques incrementadas de procesos que están destinados a ser confinados por AppArmor. Esto se debe a la lógica común para manejar operaciones 'restart' eliminando perfiles AppArmor que no se encuentran en las ubicaciones típicas del sistema de archivos, como /etc/apparmor.d/. Proyectos de espacio de usuario que gestionan sus propios perfiles AppArmor en directorios atípicos, como hacen LXD y Docker, están afectados por esta falla en la lógica de init script de AppArmor.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-07 CVE Reserved
- 2017-03-24 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97223 | Vdb Entry | |
https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6507.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3647 | 2019-10-03 | |
http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3648 | 2019-10-03 | |
https://bugs.launchpad.net/apparmor/+bug/1668892 | 2019-10-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apparmor Search vendor "Apparmor" | Apparmor Search vendor "Apparmor" for product "Apparmor" | <= 2.11 Search vendor "Apparmor" for product "Apparmor" and version " <= 2.11" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Core Search vendor "Canonical" for product "Ubuntu Core" | 15.04 Search vendor "Canonical" for product "Ubuntu Core" and version "15.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Touch Search vendor "Canonical" for product "Ubuntu Touch" | 15.04 Search vendor "Canonical" for product "Ubuntu Touch" and version "15.04" | - |
Affected
|