LWN.net Logo

abrt: information leak

Package(s):abrt, libreport, btparser, python-meh CVE #(s):CVE-2012-1106
Created:June 20, 2012 Updated:December 12, 2012
Description: From the Red Hat advisory:

If the C handler plug-in in ABRT was enabled (the abrt-addon-ccpp package installed and the abrt-ccpp service running), and the sysctl fs.suid_dumpable option was set to "2" (it is "0" by default), core dumps of set user ID (setuid) programs were created with insecure group ID permissions. This could allow local, unprivileged users to obtain sensitive information from the core dump files of setuid processes they would otherwise not be able to access.

Alerts:
Red Hat RHSA-2012:0841-04 2012-06-20
Oracle ELSA-2012-0841 2012-07-02
Scientific Linux SL-abrt-20120709 2012-07-09
CentOS CESA-2012:0841 2012-07-10
Mageia MGASA-2012-0357 2012-12-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds