PT-2013-1145 · Red Hat+1 · Libreport+27

Jan Lieskovsky

+1

·

Published

2013-01-31

·

Updated

2013-03-19

·

CVE-2012-5659

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions abrt versions 2.0.8 and earlier abrt-addon-ccpp versions 2.0.8 and earlier abrt-addon-kerneloops versions 2.0.8 and earlier abrt-addon-python versions 2.0.8 and earlier abrt-addon-vmcore versions 2.0.8 and earlier abrt-cli versions 2.0.8 and earlier abrt-debuginfo versions 2.0.8 and earlier abrt-devel versions 2.0.8 and earlier abrt-desktop versions 2.0.8 and earlier abrt-gui versions 2.0.8 and earlier abrt-libs versions 2.0.8 and earlier abrt-tui versions 2.0.8 and earlier libreport versions 2.0.9 and earlier libreport-cli versions 2.0.9 and earlier libreport-debuginfo versions 2.0.9 and earlier libreport-devel versions 2.0.9 and earlier libreport-gtk versions 2.0.9 and earlier libreport-gtk-devel versions 2.0.9 and earlier libreport-newt versions 2.0.9 and earlier libreport-plugin-bugzilla versions 2.0.9 and earlier libreport-plugin-kerneloops versions 2.0.9 and earlier libreport-plugin-logger versions 2.0.9 and earlier libreport-plugin-mailx versions 2.0.9 and earlier libreport-plugin-reportuploader versions 2.0.9 and earlier libreport-plugin-rhtsupport versions 2.0.9 and earlier libreport-python versions 2.0.9 and earlier
Description The issue is related to multiple vulnerabilities in various packages of the Automatic Bug Reporting Tool (ABRT) and libreport. These vulnerabilities can be exploited locally, potentially leading to a breach of confidentiality, integrity, and availability of protected information. According to the information provided, the exploitation can be carried out by modifying the PYTHONPATH environment variable to reference a malicious Python module, allowing local users to load and execute arbitrary Python modules.
Recommendations For abrt versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-ccpp versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-kerneloops versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-python versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-vmcore versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-cli versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-debuginfo versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-devel versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-desktop versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-gui versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-libs versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-tui versions 2.0.8 and earlier, update to a version later than 2.0.8. For libreport versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-cli versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-debuginfo versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-devel versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-gtk versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-gtk-devel versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-newt versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-bugzilla versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-kerneloops versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-logger versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-mailx versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-reportuploader versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-rhtsupport versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-python versions 2.0.9 and earlier, update to a version later than 2.0.9. As a temporary workaround, consider restricting access to the PYTHONPATH environment variable to prevent local users from loading and executing arbitrary Python modules.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-05960
BDU:2015-05961
BDU:2015-05962
BDU:2015-05963
BDU:2015-05964
BDU:2015-05965
BDU:2015-05966
BDU:2015-05967
BDU:2015-05968
BDU:2015-05969
BDU:2015-05970
BDU:2015-05971
BDU:2015-05995
BDU:2015-05996
BDU:2015-05997
BDU:2015-05998
BDU:2015-05999
BDU:2015-06000
BDU:2015-06001
BDU:2015-06002
BDU:2015-06003
BDU:2015-06004
BDU:2015-06005
BDU:2015-06006
BDU:2015-06007
BDU:2015-06008
BDU:2015-08912
BDU:2015-08913
BDU:2015-08914
BDU:2015-08915
BDU:2015-08916
BDU:2015-08917
BDU:2015-08918
BDU:2015-08919
BDU:2015-08920
BDU:2015-08921
BDU:2015-08922
BDU:2015-08923
BDU:2015-08924
BDU:2015-08925
CESA-2013_0215
CVE-2012-5659
RHSA-2013:0215
RHSA-2013_0215

Affected Products

Centos
Red Hat
Abrt
Abrt-Addon-Ccpp
Abrt-Addon-Kerneloops
Abrt-Addon-Python
Abrt-Addon-Vmcore
Abrt-Cli
Abrt-Debuginfo
Abrt-Desktop
Abrt-Devel
Abrt-Gui
Abrt-Libs
Abrt-Tui
Libreport
Libreport-Cli
Libreport-Debuginfo
Libreport-Devel
Libreport-Gtk
Libreport-Gtk-Devel
Libreport-Newt
Libreport-Plugin-Bugzilla
Libreport-Plugin-Kerneloops
Libreport-Plugin-Logger
Libreport-Plugin-Mailx
Libreport-Plugin-Reportuploader
Libreport-Plugin-Rhtsupport
Libreport-Python