CVE-2015-1870
published 2017-06-26CVE-2015-1870: The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.42%
34.1th percentile
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | automatic_bug_reporting_tool | <= 2.1.11 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6ww-8wv5-ggw9: The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allo
ghsa_unreviewed·2022-05-14
CVE-2015-1870 [MEDIUM] CWE-200 GHSA-v6ww-8wv5-ggw9: The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allo
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
Red Hat
abrt: default abrt event scripts lead to information disclosure
vendor_redhat·2015-04-17·CVSS 5.5
CVE-2015-1870 [MEDIUM] CWE-200 abrt: default abrt event scripts lead to information disclosure
abrt: default abrt event scripts lead to information disclosure
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
It was found that the ABRT event scripts created a user-readable copy of an sosreport file in ABRT problem directories, and included excerpts of /var/log/messages selected by the user-controlled process name, leading to an information disclosure. The fix for this issue prevents non-privileged users from accessing any crash reports, even reports of crashes of processes owned by those users. Only administrators (the wheel group members) are allowed to access crash reports via the "Syste
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5273 abrt: Insecure temporary directory usage in abrt-action-install-debuginfo-to-abrt-cache
bugzilla·2015-09-11·CVSS 3.6
CVE-2015-5273 [LOW] CVE-2015-5273 abrt: Insecure temporary directory usage in abrt-action-install-debuginfo-to-abrt-cache
CVE-2015-5273 abrt: Insecure temporary directory usage in abrt-action-install-debuginfo-to-abrt-cache
Multiple vulnerabilities were found in abrt allowing privilege escalation.
1. Insecure temporary directory and symlink usage in sosreport
A vulnerability allowing to elevate privileges from an unprivileged user to root on a default installation of RHEL 7/7.1 was reported.
When a process receives SIGSEGV, abrt will save diagnostic information in /var/tmp/abrt/ccpp-*$pid on RHEL 7. Unless /etc/abrt/abrt.conf contains the line "PrivateReports = yes", directories created here by abrt will be chown()'d to the user who owned the crashing process. After saving some initial information it will call post-create scripts, one of the default ones on RHEL is /usr/sbin/sosreport. /usr/sbin/sosrepor
Bugzilla
CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure [fedora-all]
bugzilla·2015-04-17·CVSS 5.5
CVE-2015-1870 [MEDIUM] CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure [fedora-all]
CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure
bugzilla·2015-04-17·CVSS 5.5
CVE-2015-1870 [MEDIUM] CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure
CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure
It was discovered that the abrt event scripts create a user-readable
copy of a sosreport file in abrt problem directories, and include
excerpts of /var/log/messages selected by the user-controlled process
name, leading to an information disclosure.
Acknowledgement:
This issue was discovered by Florian Weimer of Red Hat Product Security.
Discussion:
Created abrt tracking bugs for this issue:
Affects: fedora-all [bug 1212871]
---
This upstream commit https://github.com/abrt/abrt/commit/8939398b82006ba1fec4ed491339fc075f43fc7c changes the owner to root.
This upstream commit https://github.com/abrt/abrt/commit/7d023c32a565e83306cddf34c894477b7aaf33d1 moves /var/tmp/abrt to /var/spool/abrt.
This upstream com
http://rhn.redhat.com/errata/RHSA-2015-1083.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1210.htmlhttp://www.securityfocus.com/bid/75119https://bugzilla.redhat.com/show_bug.cgi?id=1212868https://github.com/abrt/abrt/commit/7d023c32a565e83306cddf34c894477b7aaf33d1https://github.com/abrt/abrt/commit/8939398b82006ba1fec4ed491339fc075f43fc7chttps://github.com/abrt/libreport/commit/c962918bc70a61a8cc647898ee8b1ff1c14a87c5http://rhn.redhat.com/errata/RHSA-2015-1083.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1210.htmlhttp://www.securityfocus.com/bid/75119https://bugzilla.redhat.com/show_bug.cgi?id=1212868https://github.com/abrt/abrt/commit/7d023c32a565e83306cddf34c894477b7aaf33d1https://github.com/abrt/abrt/commit/8939398b82006ba1fec4ed491339fc075f43fc7chttps://github.com/abrt/libreport/commit/c962918bc70a61a8cc647898ee8b1ff1c14a87c5
2017-06-26
Published