CVE-2012-5660
published 2013-03-12CVE-2012-5660: abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.31%
23.3th percentile
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | automatic_bug_reporting_tool | <= 2.0.9 | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
| redhat | automatic_bug_reporting_tool | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2x9c-9952-j585: abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2
ghsa_unreviewed·2022-05-17
CVE-2012-5660 [MEDIUM] GHSA-2x9c-9952-j585: abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
Red Hat
abrt: Race condition in abrt-action-install-debuginfo
vendor_redhat·2013-01-30·CVSS 6.9
CVE-2012-5660 [MEDIUM] CWE-426 abrt: Race condition in abrt-action-install-debuginfo
abrt: Race condition in abrt-action-install-debuginfo
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]
bugzilla·2013-01-31·CVSS 3.7
CVE-2012-5659 [LOW] CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]
CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supp
Bugzilla
CVE-2012-5660 abrt: Race condition in abrt-action-install-debuginfo
bugzilla·2012-12-17·CVSS 6.9
CVE-2012-5660 [MEDIUM] CVE-2012-5660 abrt: Race condition in abrt-action-install-debuginfo
CVE-2012-5660 abrt: Race condition in abrt-action-install-debuginfo
A race condition was found in the way abrt handled the directories used to store
information about crashes. A local attacker with the privileges of the abrt user
could use this flaw to perform a symbolic link attack, allowing them to make any
file writable by the abrt user, allowing them to escalate their privileges to
the privileged system user account, root.
This issue was assigned CVE-2012-5660.
Acknowledgements:
Red Hat would like to thank Martin Carpenter of Citco for reporting this issue.
Discussion:
The preliminary embargo date for this issue has been set up to next Wednesday, 30-th January of 2013.
---
Upstream patch:
http://git.fedorahosted.org/cgit/libreport.git/commit/?id=3bbf961b1884dd32654dd39b360dd7
http://git.fedorahosted.org/cgit/libreport.git/commit/?id=3bbf961b1884dd32654dd39b360dd78ef294b10ahttp://rhn.redhat.com/errata/RHSA-2013-0215.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=887866http://git.fedorahosted.org/cgit/libreport.git/commit/?id=3bbf961b1884dd32654dd39b360dd78ef294b10ahttp://rhn.redhat.com/errata/RHSA-2013-0215.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=887866
2013-03-12
Published