Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3150

Опубликовано: 22 апр. 2015
Источник: redhat
CVSS2: 6.6
EPSS Низкий

Описание

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

It was discovered that the abrt-dbus D-Bus service did not properly check the validity of the problem directory argument in the ChownProblemDir, DeleteElement, and DeleteProblem methods. A local attacker could use this flaw take ownership of arbitrary files and directories, or to delete files and directories as the root user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6abrtNot affected
Red Hat Enterprise Linux 7abrtFixedRHSA-2015:108309.06.2015
Red Hat Enterprise Linux 7libreportFixedRHSA-2015:108309.06.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1214457abrt: abrt-dbus does not guard against crafted problem directory path arguments

EPSS

Процентиль: 14%
0.00047
Низкий

6.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.1
nvd
больше 5 лет назад

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

CVSS3: 7.1
github
больше 3 лет назад

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

oracle-oval
около 10 лет назад

ELSA-2015-1083: abrt security update (IMPORTANT)

EPSS

Процентиль: 14%
0.00047
Низкий

6.6 Medium

CVSS2