CVE-2015-3147
published 2020-01-14CVE-2015-3147: daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.07%
61.0th percentile
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abrt | abrt | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hw2r-7jp6-9r7m: daemon/abrt-handle-upload
ghsa_unreviewed·2022-05-24
CVE-2015-3147 [MEDIUM] CWE-59 GHSA-hw2r-7jp6-9r7m: daemon/abrt-handle-upload
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
Red Hat
abrt: does not validate contents of uploaded problem reports
vendor_redhat·2015-04-17·CVSS 6.5
CVE-2015-3147 [MEDIUM] CWE-283 abrt: does not validate contents of uploaded problem reports
abrt: does not validate contents of uploaded problem reports
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
It was discovered that, when moving problem reports between certain directories, abrt-handle-upload did not verify that the new problem directory had appropriate permissions and did not contain symbolic links. An attacker able to create a crafted problem report could use this flaw to expose other parts of ABRT, or to overwrite arbitrary files on the system.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-1083.htmlhttp://www.openwall.com/lists/oss-security/2015/04/17/5https://bugzilla.redhat.com/show_bug.cgi?id=1212953https://github.com/abrt/abrt/commit/3746b7627218438ae7d781fc8b18a221454e9091https://github.com/abrt/abrt/pull/955http://rhn.redhat.com/errata/RHSA-2015-1083.htmlhttp://www.openwall.com/lists/oss-security/2015/04/17/5https://bugzilla.redhat.com/show_bug.cgi?id=1212953https://github.com/abrt/abrt/commit/3746b7627218438ae7d781fc8b18a221454e9091https://github.com/abrt/abrt/pull/955
2020-01-14
Published