RCE on default Ubuntu Desktop >= 12.10 Quantal
Critical
Vulnerability Details
I recently reported a number of vulnerabilities in Canonical's Apport crash report software. These bugs provided RCE on a default install of Ubuntu Desktop >= 12.10 upon opening a malicious file. I reported the issues to the Apport maintainers and we coordinate the disclosure of these issues.
Is the Internet Bug Bounty interested in providing bounties for RCE bugs affecting default Ubuntu installations? I have included a link to the Launchpad ticket and my blog post describing the issues in detail. Please let me know if this is something that you are interested in. I am happy to provide any further information that you require.
https://bugs.launchpad.net/bugs/1648806
https://donncha.is/2016/12/compromising-ubuntu-desktop/
Actions
View on HackerOneReport Stats
- Report ID: 192512
- State: Closed
- Substate: resolved
- Upvotes: 6