PT-2013-1146 · Red Hat+1 · Libreport+27

Martin Carpenter

·

Published

2013-01-31

·

Updated

2023-02-13

·

CVE-2012-5660

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions abrt versions 2.0.8 and earlier abrt-addon-ccpp versions 2.0.8 and earlier abrt-addon-kerneloops versions 2.0.8 and earlier abrt-addon-python versions 2.0.8 and earlier abrt-addon-vmcore versions 2.0.8 and earlier abrt-cli versions 2.0.8 and earlier abrt-debuginfo versions 2.0.8 and earlier abrt-devel versions 2.0.8 and earlier abrt-desktop versions 2.0.8 and earlier abrt-gui versions 2.0.8 and earlier abrt-libs versions 2.0.8 and earlier abrt-tui versions 2.0.8 and earlier libreport versions 2.0.9 and earlier libreport-cli versions 2.0.9 and earlier libreport-debuginfo versions 2.0.9 and earlier libreport-devel versions 2.0.9 and earlier libreport-gtk versions 2.0.9 and earlier libreport-gtk-devel versions 2.0.9 and earlier libreport-newt versions 2.0.9 and earlier libreport-plugin-bugzilla versions 2.0.9 and earlier libreport-plugin-kerneloops versions 2.0.9 and earlier libreport-plugin-logger versions 2.0.9 and earlier libreport-plugin-mailx versions 2.0.9 and earlier libreport-plugin-reportuploader versions 2.0.9 and earlier libreport-plugin-rhtsupport versions 2.0.9 and earlier libreport-python versions 2.0.9 and earlier
Description The issue concerns multiple vulnerabilities in various packages of the Automatic Bug Reporting Tool (ABRT) and libreport, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. The exploitation may allow attackers to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on the directories used to store information about crashes.
Recommendations For abrt versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-ccpp versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-kerneloops versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-python versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-addon-vmcore versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-cli versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-debuginfo versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-devel versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-desktop versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-gui versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-libs versions 2.0.8 and earlier, update to a version later than 2.0.8. For abrt-tui versions 2.0.8 and earlier, update to a version later than 2.0.8. For libreport versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-cli versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-debuginfo versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-devel versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-gtk versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-gtk-devel versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-newt versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-bugzilla versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-kerneloops versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-logger versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-mailx versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-reportuploader versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-plugin-rhtsupport versions 2.0.9 and earlier, update to a version later than 2.0.9. For libreport-python versions 2.0.9 and earlier, update to a version later than 2.0.9. As a temporary workaround, consider disabling the abrt-action-install-debuginfo function until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05960
BDU:2015-05961
BDU:2015-05962
BDU:2015-05963
BDU:2015-05964
BDU:2015-05965
BDU:2015-05966
BDU:2015-05967
BDU:2015-05968
BDU:2015-05969
BDU:2015-05970
BDU:2015-05971
BDU:2015-05995
BDU:2015-05996
BDU:2015-05997
BDU:2015-05998
BDU:2015-05999
BDU:2015-06000
BDU:2015-06001
BDU:2015-06002
BDU:2015-06003
BDU:2015-06004
BDU:2015-06005
BDU:2015-06006
BDU:2015-06007
BDU:2015-06008
BDU:2015-08912
BDU:2015-08913
BDU:2015-08914
BDU:2015-08915
BDU:2015-08916
BDU:2015-08917
BDU:2015-08918
BDU:2015-08919
BDU:2015-08920
BDU:2015-08921
BDU:2015-08922
BDU:2015-08923
BDU:2015-08924
BDU:2015-08925
CESA-2013_0215
CVE-2012-5660
RHSA-2013:0215
RHSA-2013_0215

Affected Products

Centos
Red Hat
Abrt
Abrt-Addon-Ccpp
Abrt-Addon-Kerneloops
Abrt-Addon-Python
Abrt-Addon-Vmcore
Abrt-Cli
Abrt-Debuginfo
Abrt-Desktop
Abrt-Devel
Abrt-Gui
Abrt-Libs
Abrt-Tui
Libreport
Libreport-Cli
Libreport-Debuginfo
Libreport-Devel
Libreport-Gtk
Libreport-Gtk-Devel
Libreport-Newt
Libreport-Plugin-Bugzilla
Libreport-Plugin-Kerneloops
Libreport-Plugin-Logger
Libreport-Plugin-Mailx
Libreport-Plugin-Reportuploader
Libreport-Plugin-Rhtsupport
Libreport-Python