CVE-2015-3147

Related Vulnerabilities: CVE-2015-3147  

Impact: Low Public Date: 2015-04-17 CWE: CWE-283 Bugzilla: 1212953: CVE-2015-3147 abrt: does not validate contents of uploaded problem reports It was discovered that, when moving problem reports between certain directories, abrt-handle-upload did not verify that the new problem directory had appropriate permissions and did not contain symbolic links. An attacker able to create a crafted problem report could use this flaw to expose other parts of ABRT, or to overwrite arbitrary files on the system.

It was discovered that, when moving problem reports between certain directories, abrt-handle-upload did not verify that the new problem directory had appropriate permissions and did not contain symbolic links. An attacker able to create a crafted problem report could use this flaw to expose other parts of ABRT, or to overwrite arbitrary files on the system.

Find out more about CVE-2015-3147 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 3.6
Base Metrics AV:N/AC:H/Au:S/C:N/I:P/A:P
Access Vector Network
Access Complexity High
Authentication Single
Confidentiality Impact None
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (abrt) RHSA-2015:1210 2015-07-07
Red Hat Enterprise Linux 7 (abrt) RHSA-2015:1083 2015-06-09

Acknowledgements

This issue was discovered by Florian Weimer of Red Hat Product Security.