CVE-2012-5660

Severity
6.9MEDIUM
EPSS
0.0%
top 91.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMay 17

Description

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2x9c-9952-j585: abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 22022-05-17
CVEList
CVE-2012-5660: abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 22013-03-12

📋Vendor Advisories

1
Red Hat
abrt: Race condition in abrt-action-install-debuginfo2013-01-30

💬Community

2
Bugzilla
CVE-2012-5659 CVE-2012-5660 abrt various flaws [fedora-all]2013-01-31
Bugzilla
CVE-2012-5660 abrt: Race condition in abrt-action-install-debuginfo2012-12-17
CVE-2012-5660 (MEDIUM CVSS 6.9) | abrt-action-install-debuginfo in Au | cvebase.io