CVE-2015-3151
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- redhat/automatic bug reporting tool
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-3151Issue Tracking, Third Party Advisory
- https://github.com/abrt/abrt/commit/7a47f57975be0d285a2f20758e4572dca6d9cdd3Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/c796c76341ee846cfb897ed645bac211d7d0a932Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/f3c2a6af3455b2882e28570e8a04f1c2d4500d5bPatch, Third Party Advisory
- https://github.com/abrt/libreport/commit/239c4f7d1f47265526b39ad70106767d00805277Patch, Third Party Advisory
- https://github.com/abrt/libreport/commit/54ecf8d017580b495d6501e53ca54e453a73a364Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-3151Issue Tracking, Third Party Advisory
- https://github.com/abrt/abrt/commit/7a47f57975be0d285a2f20758e4572dca6d9cdd3Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/c796c76341ee846cfb897ed645bac211d7d0a932Patch, Third Party Advisory
- https://github.com/abrt/abrt/commit/f3c2a6af3455b2882e28570e8a04f1c2d4500d5bPatch, Third Party Advisory
- https://github.com/abrt/libreport/commit/239c4f7d1f47265526b39ad70106767d00805277Patch, Third Party Advisory
- https://github.com/abrt/libreport/commit/54ecf8d017580b495d6501e53ca54e453a73a364Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.