CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:N/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
5.1%
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp.
Vendor | Product | Version | CPE |
---|---|---|---|
redhat | automatic_bug_reporting_tool | * | cpe:2.3:a:redhat:automatic_bug_reporting_tool:*:*:*:*:*:*:*:* |
redhat | enterprise_linux_desktop | 7.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
redhat | enterprise_linux_hpc_node | 7.0 | cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:* |
redhat | enterprise_linux_server | 7.0 | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
redhat | enterprise_linux_workstation | 7.0 | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* |
lists.fedoraproject.org/pipermail/package-announce/2015-November/172809.html
rhn.redhat.com/errata/RHSA-2015-2505.html
www.openwall.com/lists/oss-security/2015/12/01/1
www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
www.securityfocus.com/bid/78113
bugzilla.redhat.com/show_bug.cgi?id=1262252
github.com/abrt/abrt/commit/50ee8130fb4cd4ef1af7682a2c85dd99cb99424e