CVE-2013-4209
published 2018-05-01CVE-2013-4209: Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
PriorityP411low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.31%
22.7th percentile
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | automatic_bug_reporting_tool | < 2.1.6 | 2.1.6 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcf3-q2c7-v458: Automatic Bug Reporting Tool (ABRT) before 2
ghsa_unreviewed·2022-05-14
CVE-2013-4209 [LOW] CWE-200 GHSA-pcf3-q2c7-v458: Automatic Bug Reporting Tool (ABRT) before 2
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
Red Hat
ABRT: (substantially) limited leak of unauthorized information
vendor_redhat·2013-09-06·CVSS 3.3
CVE-2013-4209 [LOW] CWE-200 ABRT: (substantially) limited leak of unauthorized information
ABRT: (substantially) limited leak of unauthorized information
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
Statement: Not vulnerable. This issue did not affect the versions of abrt as shipped with Red Hat Enterprise Linux 6.
Package: abrt (Red Hat Enterprise Linux 6) - Not affected
Package: abrt (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
libqb: privileged IPC client naively prone to truncating/deleting semi-arbitrary files even if otherwise protected from an unprivileged IPC server
bugzilla·2019-05-29·CVSS 3.3
[LOW] libqb: privileged IPC client naively prone to truncating/deleting semi-arbitrary files even if otherwise protected from an unprivileged IPC server
libqb: privileged IPC client naively prone to truncating/deleting semi-arbitrary files even if otherwise protected from an unprivileged IPC server
A flaw was found in libqb in which a privileged client application linked against libqb could overwrite arbitrary files it has access to with at least partially attacker controlled data which could cause the following consequences:
- either such arbitrary file can be intentionally shrunk from original, bigger size (allowing an attacker to refine the granularity for some other brute-force extraction of the original file content, for instance, when combine with an issue akin to CVE-2013-4209.
- or such file can be blown from its original size possibly causing DoS (due to limited storage capacity), unless the underlying FS support sparse files (
Bugzilla
CVE-2013-4209 ABRT: (substantially) limited leak of unauthorized information
bugzilla·2013-08-02·CVSS 3.3
CVE-2013-4209 [LOW] CVE-2013-4209 ABRT: (substantially) limited leak of unauthorized information
CVE-2013-4209 ABRT: (substantially) limited leak of unauthorized information
A flaw was found in abrt, where a local attacker could obtain the SHA1SUM of a file they should have no access to.
Acknowledgements:
This issue was discovered by Jan Pokorný of Red Hat.
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of abrt as shipped with Red Hat Enterprise Linux 6.
---
Time to open this up.
We now ship the fixed version 2.1.6 on all previously affected products.
---
In upstream commit https://github.com/abrt/abrt/commit/776209bd00b0dd16d02dd20fdb14eecbb6b9fa18 the format of core backtraces changed significantly. Source file hashes are no longer included for python exception reports.
2018-05-01
Published