Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2012-0841

Опубликовано: 27 июн. 2012
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2012-0841: abrt, libreport, btparser, and python-meh security and bug fix update (LOW)

abrt [2.0.8-6.0.1.el6]

  • Add abrt-oracle-enterprise.patch to be product neutral
  • Remove abrt-plugin-rhtsupport dependency for cli and desktop
  • Make abrt Obsoletes/Provides abrt-plugin-rhtsupprot

[2.0.8-6]

  • enable plugin services after install rhbz#820515
  • Resolves: #820515

[2.0.8-5]

  • removed the 'report problem with ABRT btn' rhbz#809587
  • fixed double free
  • fixed ccpp-install man page
  • Resolves: #809587, #796216, #799027

[2.0.8-4]

  • dont mark reports reported in post-create by mailx as reported
  • Resolves: #803618

[2.0.8-3]

  • fixed remote crash handling rhbz#800828
  • Resolves: #800828

[2.0.8-2]

  • updated translation
  • added man page for a-a-analyze-vmcore
  • minor fixes in kernel oops parser
  • Related: #759375

[2.0.8-1]

  • rebase to the latest upstream
  • partly fixed probles with suided cores
  • fixed confusing message about 'moved copy'
  • properly enable daemons on update from previous version
  • added default config file for mailx
  • cli doesnt depend on python plugin
  • properly init i18n all plugins
  • added missing man page to abrt-cli
  • added warning when user tries to report already reported problem again
  • added vmcores plugin
  • Resolves: #759375, #783450, #773242, #771597, #770357, #751068, #749100, #747624, #727494

btparser [0.16-3]

  • Report correct crash_function in the crash sumary Resolves: rhbz#811147

[0.16-1]

  • New upstream release Resolves: #768377

libreport [2.0.9-5.0.1.el6]

  • Add oracle-enterprise.patch
  • Remove libreport-plugin-rhtsupport pkg

[2.0.9-5]

  • rebuild due to rpmdiff
  • Resolves: #823411

[2.0.9-4]

  • fixed compatibility with bugzilla 4.2
  • Resolves: #823411

[2.0.9-3]

  • added notify-only option to mailx rhbz#803618
  • Resolves: #803618

[2.0.9-2]

  • minor fix in debuginfo downloader
  • updated translations
  • Related: #759377

[2.0.9-1]

  • new upstream release
  • fixed typos in man
  • fixed handling of anaconda-tb file
  • generate valid xml file
  • Resolves: #759377, #758366, #746727

python-meh [0.12.1-3]

  • Add dbus-python and libreport to BuildRequires (vpodzime). Related: rhbz#796176

[0.12.1-2]

  • Add %check unset DISPLAY section to spec file (vpodzime). Resolves: rhbz#796176

[0.12.1-1]

  • Adapt to new libreport API (vpodzime). Resolves: rhbz#769821
  • Add info about environment variables (vpodzime). Resolves: rhbz#788577

[0.11-3]

  • Move 'import rpm' to where its needed to avoid nameserver problems. Resolves: rhbz#749330

[0.11-2]

  • Change dependency to libreport-* (mtoman) Resolves: rhbz#730924
  • Add abrt-like information to bug reports (vpodzime). Resolves: rhbz#728871

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

abrt

2.0.8-6.0.1.el6

abrt-addon-ccpp

2.0.8-6.0.1.el6

abrt-addon-kerneloops

2.0.8-6.0.1.el6

abrt-addon-python

2.0.8-6.0.1.el6

abrt-addon-vmcore

2.0.8-6.0.1.el6

abrt-cli

2.0.8-6.0.1.el6

abrt-desktop

2.0.8-6.0.1.el6

abrt-devel

2.0.8-6.0.1.el6

abrt-gui

2.0.8-6.0.1.el6

abrt-libs

2.0.8-6.0.1.el6

abrt-tui

2.0.8-6.0.1.el6

btparser

0.16-3.el6

btparser-devel

0.16-3.el6

btparser-python

0.16-3.el6

libreport

2.0.9-5.0.1.el6

libreport-cli

2.0.9-5.0.1.el6

libreport-devel

2.0.9-5.0.1.el6

libreport-gtk

2.0.9-5.0.1.el6

libreport-gtk-devel

2.0.9-5.0.1.el6

libreport-newt

2.0.9-5.0.1.el6

libreport-plugin-bugzilla

2.0.9-5.0.1.el6

libreport-plugin-kerneloops

2.0.9-5.0.1.el6

libreport-plugin-logger

2.0.9-5.0.1.el6

libreport-plugin-mailx

2.0.9-5.0.1.el6

libreport-plugin-reportuploader

2.0.9-5.0.1.el6

libreport-python

2.0.9-5.0.1.el6

python-meh

0.12.1-3.el6

Oracle Linux i686

abrt

2.0.8-6.0.1.el6

abrt-addon-ccpp

2.0.8-6.0.1.el6

abrt-addon-kerneloops

2.0.8-6.0.1.el6

abrt-addon-python

2.0.8-6.0.1.el6

abrt-addon-vmcore

2.0.8-6.0.1.el6

abrt-cli

2.0.8-6.0.1.el6

abrt-desktop

2.0.8-6.0.1.el6

abrt-devel

2.0.8-6.0.1.el6

abrt-gui

2.0.8-6.0.1.el6

abrt-libs

2.0.8-6.0.1.el6

abrt-tui

2.0.8-6.0.1.el6

btparser

0.16-3.el6

btparser-devel

0.16-3.el6

btparser-python

0.16-3.el6

libreport

2.0.9-5.0.1.el6

libreport-cli

2.0.9-5.0.1.el6

libreport-devel

2.0.9-5.0.1.el6

libreport-gtk

2.0.9-5.0.1.el6

libreport-gtk-devel

2.0.9-5.0.1.el6

libreport-newt

2.0.9-5.0.1.el6

libreport-plugin-bugzilla

2.0.9-5.0.1.el6

libreport-plugin-kerneloops

2.0.9-5.0.1.el6

libreport-plugin-logger

2.0.9-5.0.1.el6

libreport-plugin-mailx

2.0.9-5.0.1.el6

libreport-plugin-reportuploader

2.0.9-5.0.1.el6

libreport-python

2.0.9-5.0.1.el6

python-meh

0.12.1-3.el6

Oracle Linux sparc64

python-meh

0.12.1-3.el6

Связанные CVE

Связанные уязвимости

redhat
почти 14 лет назад

The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.

nvd
больше 13 лет назад

The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.

redhat
почти 14 лет назад

ABRT might allow attackers to obtain sensitive information from crash reports.

CVSS3: 7.5
nvd
почти 6 лет назад

ABRT might allow attackers to obtain sensitive information from crash reports.

github
больше 3 лет назад

The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.