PT-2020-7832 · Abrt+2 · Abrt+2

Florian Weimer

·

Published

2015-06-09

·

Updated

2023-02-13

·

CVE-2015-3151

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: ABRT (affected versions not specified)
Description: A directory traversal issue in abrt-dbus within the Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files. This can be achieved via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CESA-2015_1083
CVE-2015-3151
RHSA-2015:1083
RHSA-2015_1083

Affected Products

Abrt
Centos
Red Hat