Synced 12 Sept 2026 01:32 UTC Account
← All products

CVE-2015-1870

MEDIUM severity · CVSS 5.5 · Information disclosure
5.5CVSS MEDIUM

Summary

The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://github.com/abrt/abrt/commit/7d023c32a565e83306cddf34c894477b7aaf33d1 ↗