CVE-2012-5659
published 2013-03-12CVE-2012-5659: Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows…
PriorityP414low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.45%
36.0th percentile
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | automatic_bug_reporting_tool | <= 2.0.9 | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
abrt: Arbitrary Python code execution due improper sanitization of the PYTHONPATH environment variable by installing debuginfo packages into cache
vendor_redhat·2013-01-30·CVSS 3.7
CVE-2012-5659 [LOW] abrt: Arbitrary Python code execution due improper sanitization of the PYTHONPATH environment variable by installing debuginfo packages into cache
abrt: Arbitrary Python code execution due improper sanitization of the PYTHONPATH environment variable by installing debuginfo packages into cache
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.
GHSA
GHSA-p65h-g398-8mm3: Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache
ghsa_unreviewed·2022-05-17
CVE-2012-5659 [LOW] GHSA-p65h-g398-8mm3: Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]
bugzilla·2013-01-31·CVSS 3.7
CVE-2012-5659 [LOW] CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]
CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supp
Bugzilla
CVE-2012-5659 abrt: Arbitrary Python code execution due improper sanitization of the PYTHONPATH environment variable by installing debuginfo packages into cache
bugzilla·2012-09-03·CVSS 3.7
CVE-2012-5659 [LOW] CVE-2012-5659 abrt: Arbitrary Python code execution due improper sanitization of the PYTHONPATH environment variable by installing debuginfo packages into cache
CVE-2012-5659 abrt: Arbitrary Python code execution due improper sanitization of the PYTHONPATH environment variable by installing debuginfo packages into cache
An insufficient environment sanitization flaw was found in the way 'abrt-action-install-debuginfo-to-abrt-cache' tool, performing installation of required debuginfo packages into ABRT's cache, of ABRT, an automatic bug detection and reporting tool, used the PYTHONPATH environment variable. A local attacker could provide a commonly used Python module with specially-crafted content in non-standard system location / path, which would lead into arbitrary Python code execution with privileges of the 'abrt' user, when the 'abrt-action-install-debuginfo-to-abrt-cache' tool was run from the parent directory of the folder, containing the m
http://git.fedorahosted.org/cgit/abrt.git/commit/?id=b173d81b577953b96a282167c7eecd66bf111a4fhttp://rhn.redhat.com/errata/RHSA-2013-0215.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=854011http://git.fedorahosted.org/cgit/abrt.git/commit/?id=b173d81b577953b96a282167c7eecd66bf111a4fhttp://rhn.redhat.com/errata/RHSA-2013-0215.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=854011
2013-03-12
Published