Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3147

Опубликовано: 17 апр. 2015
Источник: redhat
CVSS2: 3.6
EPSS Низкий

Описание

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.

It was discovered that, when moving problem reports between certain directories, abrt-handle-upload did not verify that the new problem directory had appropriate permissions and did not contain symbolic links. An attacker able to create a crafted problem report could use this flaw to expose other parts of ABRT, or to overwrite arbitrary files on the system.

Дополнительная информация

Статус:

Low
Дефект:
CWE-283
https://bugzilla.redhat.com/show_bug.cgi?id=1212953abrt: does not validate contents of uploaded problem reports

EPSS

Процентиль: 66%
0.00535
Низкий

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.

CVSS3: 6.5
github
больше 3 лет назад

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.

oracle-oval
около 10 лет назад

ELSA-2015-1210: abrt security update (MODERATE)

oracle-oval
около 10 лет назад

ELSA-2015-1083: abrt security update (IMPORTANT)

EPSS

Процентиль: 66%
0.00535
Низкий

3.6 Low

CVSS2