Redhat

Automatic Bug Reporting Tool

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 13.06.2026 02:34:37
  • Zuletzt bearbeitet 21.09.2026 06:17:01

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory wi...

  • EPSS 0.14%
  • Veröffentlicht 13.06.2026 02:34:35
  • Zuletzt bearbeitet 21.09.2026 06:17:01

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell pr...

  • EPSS 0.63%
  • Veröffentlicht 03.12.2025 08:33:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged loc...

  • EPSS 1.62%
  • Veröffentlicht 31.01.2020 17:15:13
  • Zuletzt bearbeitet 26.08.2026 20:06:00

ABRT might allow attackers to obtain sensitive information from crash reports.

  • EPSS 0.39%
  • Veröffentlicht 14.01.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 02:28:47

The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.

  • EPSS 0.56%
  • Veröffentlicht 14.01.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 02:28:46

Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) Dele...

  • EPSS 0.4%
  • Veröffentlicht 14.01.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 02:28:46

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

  • EPSS 1.07%
  • Veröffentlicht 14.01.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 02:28:46

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/sp...

  • EPSS 0.41%
  • Veröffentlicht 14.01.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 02:26:18

The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.

  • EPSS 0.31%
  • Veröffentlicht 01.05.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 01:55:08

Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.