CVE-2015-3150
HIGH severity · CVSS 7.1 · Improper input validation
7.1CVSS HIGH
Summary
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://github.com/abrt/abrt/commit/6e811d78e2719988ae291181f5b133af32ce62d8 ↗
Additional information
- NVD record
- https://github.com/abrt/abrt/commit/6e811d78e2719988ae291181f5b133af32ce62d8Patch
- https://github.com/abrt/abrt/commit/7814554e0827ece778ca88fd90832bd4d05520b1Patch
- https://github.com/abrt/abrt/commit/b7f8bd20b7fb5b72f003ae3fa647c1d75f4218b7Patch
- https://github.com/abrt/libreport/commit/1951e7282043dfe1268d492aea056b554baedb75Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=1214457Advisory