PT-2015-6840 · Red Hat+1 · Libreport+2

·

CVE-2015-5302

·

Publicado

2015-11-23

·

Atualizado

2023-02-13

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions libreport versions 2.0.7 through 2.6.3
Description The issue allows remote attackers to obtain sensitive information via unspecified vectors related to the backtrace, cmdline, environ, open fds, maps, smaps, hostname, remote, ks.cfg, or anaconda-tb file attachment included in a Red Hat Bugzilla bug report. This occurs because libreport only saves changes to the first file when editing a crash report.
Recommendations For versions 2.0.7 through 2.6.3, update to version 2.6.3 or later to resolve the issue.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2015_2504
CESA-2015_2505
CVE-2015-5302
RHSA-2015:2504
RHSA-2015:2505
RHSA-2015_2504
RHSA-2015_2505

Produtos afetados

Centos
Red Hat
Libreport