Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3142

Опубликовано: 17 апр. 2015
Источник: redhat
CVSS2: 1.2
EPSS Низкий

Описание

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

It was discovered that the kernel-invoked coredump processor provided by ABRT wrote core dumps to files owned by other system users. This could result in information disclosure if an application crashed while its current directory was a directory writable to by other users (such as /tmp).

Дополнительная информация

Статус:

Low
Дефект:
CWE-282->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1212818abrt: abrt-hook-ccpp writes core dumps to existing files owned by others

EPSS

Процентиль: 30%
0.00111
Низкий

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 4.7
nvd
больше 8 лет назад

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

CVSS3: 4.7
github
больше 3 лет назад

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

oracle-oval
больше 10 лет назад

ELSA-2015-1210: abrt security update (MODERATE)

oracle-oval
больше 10 лет назад

ELSA-2015-1083: abrt security update (IMPORTANT)

EPSS

Процентиль: 30%
0.00111
Низкий

1.2 Low

CVSS2