CVE-2015-3142
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to…
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/automatic bug reporting tool
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-1083.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1210.html
- http://www.openwall.com/lists/oss-security/2015/04/17/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/75116Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1212818Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1083.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1210.html
- http://www.openwall.com/lists/oss-security/2015/04/17/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/75116Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1212818Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.