libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libreport-compatUpgrade libreport-plugin-mailxUpgrade libreport-filesystemUpgrade libreport-plugin-rhtsupportUpgrade libreport-gtk-develUpgrade libreport-plugin-bugzillaUpgrade libreportUpgrade libreport-plugin-kerneloopsUpgrade libreport-pythonUpgrade libreport-develUpgrade libreport-gtkUpgrade libreport-newtUpgrade libreport-plugin-reportuploaderUpgrade libreport-plugin-loggerUpgrade libreport-cliUpgrade libreport-plugin-ureport | Dec 1, 2016 | Dec 7, 2015 |
| Oracle_linux | — | Upgrade libreport-rhel-anaconda-bugzillaUpgrade libreport-plugin-bugzillaUpgrade libreport-webUpgrade libreport-plugin-reportuploaderUpgrade libreport-newtUpgrade abrt-addon-xorgUpgrade libreport-plugin-ureportUpgrade libreport-rhel-bugzillaUpgrade abrt-retrace-clientUpgrade libreport-pythonUpgrade abrt-addon-upload-watchUpgrade abrt-gui-libsUpgrade libreport-filesystemUpgrade libreport-anacondaUpgrade abrt-tuiUpgrade libreport-plugin-loggerUpgrade libreport-plugin-kerneloopsUpgrade libreport-plugin-mailxUpgrade libreportUpgrade abrt-desktopUpgrade abrt-guiUpgrade abrt-libsUpgrade abrt-python-docUpgrade libreport-gtkUpgrade libreport-gtk-develUpgrade libreport-compatUpgrade abrt-gui-develUpgrade abrt-addon-kerneloopsUpgrade abrtUpgrade abrt-addon-pythonUpgrade abrt-addon-vmcoreUpgrade abrt-addon-ccppUpgrade abrt-dbusUpgrade abrt-cliUpgrade abrt-console-notificationUpgrade libreport-develUpgrade abrt-develUpgrade abrt-addon-pstoreoopsUpgrade libreport-web-develUpgrade abrt-pythonUpgrade libreport-cli | Oct 16, 2024 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub