abrt: information disclosure
| Package(s): | abrt | CVE #(s): | CVE-2011-4088 | ||||||||||||||||||||
| Created: | December 19, 2011 | Updated: | July 10, 2012 | ||||||||||||||||||||
| Description: | From the Red Hat bugzilla:
Jan Iven reported that abrt could possibly leak certain non-public information when reporting on crashes. If an application included a user name, password, or other confidential information in the crash output, abrt would send that information along with the other information it collects about the crash, to bugzilla. While the real problem is the application including this information in the crash output, abrt should not be submitting this information or should warn the user that it may be submitting potentially sensitive information and allow the user to scrub that information before it is sent. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
