CVE-2015-3142
published 2017-06-26CVE-2015-3142: The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them…
PriorityP419medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.34%
26.7th percentile
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | automatic_bug_reporting_tool | <= 2.1.11 | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
abrt: abrt-hook-ccpp writes core dumps to existing files owned by others
vendor_redhat·2015-04-17·CVSS 4.7
CVE-2015-3142 [MEDIUM] CWE-282 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others
abrt: abrt-hook-ccpp writes core dumps to existing files owned by others
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
It was discovered that the kernel-invoked coredump processor provided by ABRT wrote core dumps to files owned by other system users. This could result in information disclosure if an application crashed while its current directory was a directory writable to by other users (such as /tmp).
GHSA
GHSA-fpvf-mw5r-q2rm: The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps
ghsa_unreviewed·2022-05-14
CVE-2015-3142 [MEDIUM] CWE-200 GHSA-fpvf-mw5r-q2rm: The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others
bugzilla·2015-04-17·CVSS 4.7
CVE-2015-3142 [MEDIUM] CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others
CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others
It was discovered that the kernel-invoked coredump processor provided by
abrt writes core dumps to files owned by other system users. This could
result in information disclosure if an application crashes while its
current directory is a directory writable to other users (such as /tmp).
Acknowledgement:
This issue was discovered by Florian Weimer of Red Hat Product Security.
Discussion:
Created abrt tracking bugs for this issue:
Affects: fedora-all [bug 1212821]
---
These upstream commits fixes this cve:
https://github.com/abrt/abrt/commit/af945ff58a698ce00c45059a05994ef53a13e192
https://github.com/abrt/abrt/commit/806bb07571b698d90169c3b73cb65cd09c900284
https://github.com/abrt/abrt/commit/b72616
Bugzilla
CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others [fedora-all]
bugzilla·2015-04-17·CVSS 4.7
CVE-2015-3142 [MEDIUM] CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others [fedora-all]
CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
http://rhn.redhat.com/errata/RHSA-2015-1083.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1210.htmlhttp://www.openwall.com/lists/oss-security/2015/04/17/5http://www.securityfocus.com/bid/75116https://bugzilla.redhat.com/show_bug.cgi?id=1212818http://rhn.redhat.com/errata/RHSA-2015-1083.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1210.htmlhttp://www.openwall.com/lists/oss-security/2015/04/17/5http://www.securityfocus.com/bid/75116https://bugzilla.redhat.com/show_bug.cgi?id=1212818
2017-06-26
Published