CVE-2012-1106
published 2012-07-03CVE-2012-1106: The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files…
PriorityP44low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.44%
35.9th percentile
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | automatic_bug_reporting_tool | <= 2.0.7 | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
abrt: Setuid process core dump archived with unsafe GID permissions
vendor_redhat·2012-02-06·CVSS 1.9
CVE-2012-1106 [LOW] abrt: Setuid process core dump archived with unsafe GID permissions
abrt: Setuid process core dump archived with unsafe GID permissions
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
No documentation needed
GHSA
GHSA-rph2-33pr-67ww: The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2
ghsa_unreviewed·2022-05-17
CVE-2012-1106 [LOW] GHSA-rph2-33pr-67ww: The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1106 abrt: Setuid process core dump archived with unsafe GID permissions [fedora-all]
bugzilla·2012-03-05·CVSS 1.9
CVE-2012-1106 [LOW] CVE-2012-1106 abrt: Setuid process core dump archived with unsafe GID permissions [fedora-all]
CVE-2012-1106 abrt: Setuid process core dump archived with unsafe GID permissions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/
Bugzilla
CVE-2012-1106 abrt: Setuid process core dump archived with unsafe GID permissions
bugzilla·2012-01-27·CVSS 1.9
CVE-2012-1106 [LOW] CVE-2012-1106 abrt: Setuid process core dump archived with unsafe GID permissions
CVE-2012-1106 abrt: Setuid process core dump archived with unsafe GID permissions
A sensitive information disclosure flaw was found in the way abrt, the automatic bug detection and reporting tool, performed archiving of certain core dump files. When the abrt C handler plug-in and core dumps for setuid and setgid processes were enabled (via fs.suid_dumpable=2), an unprivileged local user could use this flaw to obtain access to core dump files of setuid processes, which terminated with crash and were run by the same unprivileged user, leading to disclosure of sensitive information due to weak GID permissions, those core dump files were created with.
Discussion:
This issue affects the version of the abrt package, as shipped with Red Hat
Enterprise Linux 6.
--
This issue affects the versi
http://rhn.redhat.com/errata/RHSA-2012-0841.htmlhttp://www.securityfocus.com/bid/54121https://exchange.xforce.ibmcloud.com/vulnerabilities/76524https://fedorahosted.org/abrt/changeset/23d6997d7886abe118c28254f7f73f0b19b2d4e0http://rhn.redhat.com/errata/RHSA-2012-0841.htmlhttp://www.securityfocus.com/bid/54121https://exchange.xforce.ibmcloud.com/vulnerabilities/76524https://fedorahosted.org/abrt/changeset/23d6997d7886abe118c28254f7f73f0b19b2d4e0
2012-07-03
Published