Redhat Automatic Bug Reporting Tool vulnerabilities
8 known vulnerabilities affecting redhat/automatic_bug_reporting_tool.
Total CVEs
8
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
MEDIUM4LOW4
Vulnerabilities
Page 1 of 1
CVE-2013-4209LOWCVSS 3.3fixed in 2.1.62018-05-01
CVE-2013-4209 [LOW] CWE-200 CVE-2013-4209: Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
nvd
CVE-2015-3142MEDIUMCVSS 4.7≤ 2.1.112017-06-26
CVE-2015-3142 [MEDIUM] CWE-200 CVE-2015-3142: The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
nvd
CVE-2015-1870MEDIUMCVSS 5.5≤ 2.1.112017-06-26
CVE-2015-1870 [MEDIUM] CWE-200 CVE-2015-1870: The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
nvd
CVE-2015-5287MEDIUMCVSS 6.9PoC≤ 2.7.02015-12-07
CVE-2015-5287 [MEDIUM] CWE-59 CVE-2015-5287: The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local use
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
nvd
CVE-2015-5273LOWCVSS 3.6PoC≤ 2.7.02015-12-07
CVE-2015-5273 [LOW] CWE-59 CVE-2015-5273: The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT)
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp.
nvd
CVE-2012-5660MEDIUMCVSS 6.9≤ 2.0.9v2.0.0+10 more2013-03-12
CVE-2012-5660 [MEDIUM] CWE-264 CVE-2012-5660: abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
nvd
CVE-2012-5659LOWCVSS 3.7≤ 2.0.9v2.0.0+10 more2013-03-12
CVE-2012-5659 [LOW] CVE-2012-5659: Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Auto
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.
nvd
CVE-2012-1106LOWCVSS 1.9≤ 2.0.72012-07-03
CVE-2012-1106 [LOW] CWE-264 CVE-2012-1106: The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not p
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
nvd