CVE-2015-3150
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/automatic bug reporting tool
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1214457Issue Tracking, Third Party Advisory
- https://github.com/abrt/abrt/commit/6e811d78e2719988ae291181f5b133af32ce62d8Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/7814554e0827ece778ca88fd90832bd4d05520b1Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/b7f8bd20b7fb5b72f003ae3fa647c1d75f4218b7Patch, Third Party Advisory
- https://github.com/abrt/libreport/commit/1951e7282043dfe1268d492aea056b554baedb75Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1214457Issue Tracking, Third Party Advisory
- https://github.com/abrt/abrt/commit/6e811d78e2719988ae291181f5b133af32ce62d8Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/7814554e0827ece778ca88fd90832bd4d05520b1Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/b7f8bd20b7fb5b72f003ae3fa647c1d75f4218b7Patch, Third Party Advisory
- https://github.com/abrt/libreport/commit/1951e7282043dfe1268d492aea056b554baedb75Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.