|
|
| |
|
| |
abrt: information leak
| Package(s): | abrt, libreport, btparser, python-meh |
CVE #(s): | CVE-2012-1106
|
| Created: | June 20, 2012 |
Updated: | December 12, 2012 |
| Description: |
From the Red Hat advisory:
If the C handler plug-in in ABRT was enabled (the abrt-addon-ccpp package
installed and the abrt-ccpp service running), and the sysctl
fs.suid_dumpable option was set to "2" (it is "0" by default), core dumps
of set user ID (setuid) programs were created with insecure group ID
permissions. This could allow local, unprivileged users to obtain sensitive
information from the core dump files of setuid processes they would
otherwise not be able to access. |
| Alerts: |
|
( Log in to post comments)
|
|
|