The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp.
CVSS Details
- CVSS 3.1 Base Score: 5.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade libreport-pythonUpgrade libreport-web-develUpgrade libreport-plugin-ureportUpgrade libreportUpgrade abrt-develUpgrade libreport-rhel-bugzillaUpgrade abrt-addon-pstoreoopsUpgrade abrt-console-notificationUpgrade libreport-plugin-reportuploaderUpgrade libreport-plugin-bugzillaUpgrade libreport-newtUpgrade libreport-cliUpgrade abrt-addon-upload-watchUpgrade libreport-rhel-anaconda-bugzillaUpgrade abrt-addon-vmcoreUpgrade libreport-plugin-mailxUpgrade abrt-addon-kerneloopsUpgrade abrt-pythonUpgrade libreport-develUpgrade abrt-retrace-clientUpgrade abrt-addon-pythonUpgrade abrt-guiUpgrade libreport-webUpgrade libreport-plugin-loggerUpgrade libreport-compatUpgrade abrt-desktopUpgrade abrt-addon-ccppUpgrade libreport-gtk-develUpgrade abrtUpgrade abrt-dbusUpgrade abrt-gui-develUpgrade abrt-addon-xorgUpgrade libreport-gtkUpgrade libreport-filesystemUpgrade libreport-anacondaUpgrade abrt-cliUpgrade abrt-libsUpgrade abrt-tuiUpgrade libreport-plugin-kerneloopsUpgrade abrt-python-docUpgrade abrt-gui-libs | Oct 16, 2024 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub