|
|
Log in / Subscribe / Register

abrt: information disclosure

Package(s):abrt CVE #(s):CVE-2011-4088
Created:December 19, 2011 Updated:July 10, 2012
Description: From the Red Hat bugzilla:

Jan Iven reported that abrt could possibly leak certain non-public information when reporting on crashes. If an application included a user name, password, or other confidential information in the crash output, abrt would send that information along with the other information it collects about the crash, to bugzilla.

While the real problem is the application including this information in the crash output, abrt should not be submitting this information or should warn the user that it may be submitting potentially sensitive information and allow the user to scrub that information before it is sent.

Alerts:
CentOS CESA-2012:0841 abrt 2012-07-10
Scientific Linux SL-abrt-20120709 abrt, libreport, btparser, python-meh 2012-07-09
Red Hat RHSA-2012:0841-04 abrt, libreport, btparser, python-meh 2012-06-20
Fedora FEDORA-2011-16990 libreport 2011-12-11
Fedora FEDORA-2011-16990 abrt 2011-12-11

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds