Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3142

Опубликовано: 17 апр. 2015
Источник: redhat
CVSS2: 1.2

Описание

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

It was discovered that the kernel-invoked coredump processor provided by ABRT wrote core dumps to files owned by other system users. This could result in information disclosure if an application crashed while its current directory was a directory writable to by other users (such as /tmp).

Дополнительная информация

Статус:

Low
Дефект:
CWE-282->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1212818abrt: abrt-hook-ccpp writes core dumps to existing files owned by others

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 4.7
nvd
около 8 лет назад

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

CVSS3: 4.7
github
больше 3 лет назад

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

oracle-oval
около 10 лет назад

ELSA-2015-1210: abrt security update (MODERATE)

oracle-oval
около 10 лет назад

ELSA-2015-1083: abrt security update (IMPORTANT)

1.2 Low

CVSS2