Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-6507 Details

Description

An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-269Improper Privilege Management[email protected]

Affected Products

ProductVersions
apparmor apparmor
<= 2.11

CPE

  • cpe:2.3:a:apparmor:apparmor:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
canonical ubuntu core
15.04

CPE

  • cpe:2.3:o:canonical:ubuntu_core:15.04:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
canonical ubuntu touch
15.04

CPE

  • cpe:2.3:o:canonical:ubuntu_touch:15.04:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-6507
NVD Published Date:
Mar 24, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-6507 Details - Not Deferred