Low CentOS abrt Update

Metadata

low
unknown
abrt-2.0.8-6.el6.centos.i686.rpm, abrt-2.0.8-6.el6.centos.src.rpm, abrt-2.0.8-6.el6.centos.x86_64.rpm, abrt-addon-ccpp-2.0.8-6.el6.centos.i686.rpm, abrt-addon-ccpp-2.0.8-6.el6.centos.x86_64.rpm, abrt-addon-kerneloops-2.0.8-6.el6.centos.i686.rpm, abrt-addon-kerneloops-2.0.8-6.el6.centos.x86_64.rpm, abrt-addon-python-2.0.8-6.el6.centos.i686.rpm, abrt-addon-python-2.0.8-6.el6.centos.x86_64.rpm, abrt-addon-vmcore-2.0.8-6.el6.centos.i686.rpm, abrt-addon-vmcore-2.0.8-6.el6.centos.x86_64.rpm, abrt-cli-2.0.8-6.el6.centos.i686.rpm, abrt-cli-2.0.8-6.el6.centos.x86_64.rpm, abrt-desktop-2.0.8-6.el6.centos.i686.rpm, abrt-desktop-2.0.8-6.el6.centos.x86_64.rpm, abrt-devel-2.0.8-6.el6.centos.i686.rpm, abrt-devel-2.0.8-6.el6.centos.x86_64.rpm, abrt-gui-2.0.8-6.el6.centos.i686.rpm, abrt-gui-2.0.8-6.el6.centos.x86_64.rpm, abrt-libs-2.0.8-6.el6.centos.i686.rpm, abrt-libs-2.0.8-6.el6.centos.x86_64.rpm, abrt-tui-2.0.8-6.el6.centos.i686.rpm, abrt-tui-2.0.8-6.el6.centos.x86_64.rpm, btparser-0.16-3.el6.i686.rpm, btparser-0.16-3.el6.src.rpm, btparser-0.16-3.el6.x86_64.rpm, btparser-devel-0.16-3.el6.i686.rpm, btparser-devel-0.16-3.el6.x86_64.rpm, btparser-python-0.16-3.el6.i686.rpm, btparser-python-0.16-3.el6.x86_64.rpm, libreport-2.0.9-5.el6.centos.i686.rpm, libreport-2.0.9-5.el6.centos.src.rpm, libreport-2.0.9-5.el6.centos.x86_64.rpm, libreport-cli-2.0.9-5.el6.centos.i686.rpm, libreport-cli-2.0.9-5.el6.centos.x86_64.rpm, libreport-devel-2.0.9-5.el6.centos.i686.rpm, libreport-devel-2.0.9-5.el6.centos.x86_64.rpm, libreport-gtk-2.0.9-5.el6.centos.i686.rpm, libreport-gtk-2.0.9-5.el6.centos.x86_64.rpm, libreport-gtk-devel-2.0.9-5.el6.centos.i686.rpm, libreport-gtk-devel-2.0.9-5.el6.centos.x86_64.rpm, libreport-newt-2.0.9-5.el6.centos.i686.rpm, libreport-newt-2.0.9-5.el6.centos.x86_64.rpm, libreport-plugin-bugzilla-2.0.9-5.el6.centos.i686.rpm, libreport-plugin-bugzilla-2.0.9-5.el6.centos.x86_64.rpm, libreport-plugin-kerneloops-2.0.9-5.el6.centos.i686.rpm, libreport-plugin-kerneloops-2.0.9-5.el6.centos.x86_64.rpm, libreport-plugin-logger-2.0.9-5.el6.centos.i686.rpm, libreport-plugin-logger-2.0.9-5.el6.centos.x86_64.rpm, libreport-plugin-mailx-2.0.9-5.el6.centos.i686.rpm, libreport-plugin-mailx-2.0.9-5.el6.centos.x86_64.rpm, libreport-plugin-reportuploader-2.0.9-5.el6.centos.i686.rpm, libreport-plugin-reportuploader-2.0.9-5.el6.centos.x86_64.rpm, libreport-plugin-rhtsupport-2.0.9-5.el6.centos.i686.rpm, libreport-plugin-rhtsupport-2.0.9-5.el6.centos.x86_64.rpm, libreport-python-2.0.9-5.el6.centos.i686.rpm, libreport-python-2.0.9-5.el6.centos.x86_64.rpm
rhn.redhat.com, lists.centos.org
2012-07-10
2017-07-27 20:03
2017-07-27 19:03
2017-04-01 19:06
2017-01-05 20:10

Description


Updated abrt, libreport, btparser, and python-meh packages that fix two
security issues and several bugs are now available for Red Hat Enterprise
Linux 6.

The Red Hat Security Response Team has rated this update as having low
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality. libreport provides an API for reporting different problems
in applications to different bug targets, such as Bugzilla, FTP, and Trac.

The btparser utility is a backtrace parser and analyzer library, which
works with backtraces produced by the GNU Project Debugger. It can parse a
text file with a backtrace to a tree of C structures, allowing to analyze
the threads and frames of the backtrace and process them.

The python-meh package provides a python library for handling exceptions.

If the C handler plug-in in ABRT was enabled (the abrt-addon-ccpp package
installed and the abrt-ccpp service running), and the sysctl
fs.suid_dumpable option was set to "2" (it is "0" by default), core dumps
of set user ID (setuid) programs were created with insecure group ID
permissions. This could allow local, unprivileged users to obtain sensitive
information from the core dump files of setuid processes they would
otherwise not be able to access. (CVE-2012-1106)

ABRT did not allow users to easily search the collected crash information
for sensitive data prior to submitting it. This could lead to users
unintentionally exposing sensitive information via the submitted crash
reports. This update adds functionality to search across all the collected
data. Note that this fix does not apply to the default configuration, where
reports are sent to Red Hat Customer Support. It only takes effect for
users sending information to Red Hat Bugzilla. (CVE-2011-4088)

Red Hat would like to thank Jan Iven for reporting CVE-2011-4088.

These updated packages include numerous bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.3 Technical Notes for information on the
most significant of these changes.

All users of abrt, libreport, btparser, and python-meh are advised to
upgrade to these updated packages, which correct these issues.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
6 abrt abrt-2.0.8-6.el6.centos.i686.rpm
abrt abrt-2.0.8-6.el6.centos.src.rpm
abrt abrt-2.0.8-6.el6.centos.x86_64.rpm
abrt-addon-ccpp abrt-addon-ccpp-2.0.8-6.el6.centos.i686.rpm
abrt-addon-ccpp abrt-addon-ccpp-2.0.8-6.el6.centos.x86_64.rpm
abrt-addon-kerneloops abrt-addon-kerneloops-2.0.8-6.el6.centos.i686.rpm
abrt-addon-kerneloops abrt-addon-kerneloops-2.0.8-6.el6.centos.x86_64.rpm
abrt-addon-python abrt-addon-python-2.0.8-6.el6.centos.i686.rpm
abrt-addon-python abrt-addon-python-2.0.8-6.el6.centos.x86_64.rpm
abrt-addon-vmcore abrt-addon-vmcore-2.0.8-6.el6.centos.i686.rpm
abrt-addon-vmcore abrt-addon-vmcore-2.0.8-6.el6.centos.x86_64.rpm
abrt-cli abrt-cli-2.0.8-6.el6.centos.i686.rpm
abrt-cli abrt-cli-2.0.8-6.el6.centos.x86_64.rpm
abrt-desktop abrt-desktop-2.0.8-6.el6.centos.i686.rpm
abrt-desktop abrt-desktop-2.0.8-6.el6.centos.x86_64.rpm
abrt-devel abrt-devel-2.0.8-6.el6.centos.i686.rpm
abrt-devel abrt-devel-2.0.8-6.el6.centos.x86_64.rpm
abrt-gui abrt-gui-2.0.8-6.el6.centos.i686.rpm
abrt-gui abrt-gui-2.0.8-6.el6.centos.x86_64.rpm
abrt-libs abrt-libs-2.0.8-6.el6.centos.i686.rpm
abrt-libs abrt-libs-2.0.8-6.el6.centos.x86_64.rpm
abrt-tui abrt-tui-2.0.8-6.el6.centos.i686.rpm
abrt-tui abrt-tui-2.0.8-6.el6.centos.x86_64.rpm
btparser btparser-0.16-3.el6.i686.rpm
btparser btparser-0.16-3.el6.src.rpm
btparser btparser-0.16-3.el6.x86_64.rpm
btparser-devel btparser-devel-0.16-3.el6.i686.rpm
btparser-devel btparser-devel-0.16-3.el6.x86_64.rpm
btparser-python btparser-python-0.16-3.el6.i686.rpm
btparser-python btparser-python-0.16-3.el6.x86_64.rpm
libreport libreport-2.0.9-5.el6.centos.i686.rpm
libreport libreport-2.0.9-5.el6.centos.src.rpm
libreport libreport-2.0.9-5.el6.centos.x86_64.rpm
libreport-cli libreport-cli-2.0.9-5.el6.centos.i686.rpm
libreport-cli libreport-cli-2.0.9-5.el6.centos.x86_64.rpm
libreport-devel libreport-devel-2.0.9-5.el6.centos.i686.rpm
libreport-devel libreport-devel-2.0.9-5.el6.centos.x86_64.rpm
libreport-gtk libreport-gtk-2.0.9-5.el6.centos.i686.rpm
libreport-gtk libreport-gtk-2.0.9-5.el6.centos.x86_64.rpm
libreport-gtk-devel libreport-gtk-devel-2.0.9-5.el6.centos.i686.rpm
libreport-gtk-devel libreport-gtk-devel-2.0.9-5.el6.centos.x86_64.rpm
libreport-newt libreport-newt-2.0.9-5.el6.centos.i686.rpm
libreport-newt libreport-newt-2.0.9-5.el6.centos.x86_64.rpm
libreport-plugin-bugzilla libreport-plugin-bugzilla-2.0.9-5.el6.centos.i686.rpm
libreport-plugin-bugzilla libreport-plugin-bugzilla-2.0.9-5.el6.centos.x86_64.rpm
libreport-plugin-kerneloops libreport-plugin-kerneloops-2.0.9-5.el6.centos.i686.rpm
libreport-plugin-kerneloops libreport-plugin-kerneloops-2.0.9-5.el6.centos.x86_64.rpm
libreport-plugin-logger libreport-plugin-logger-2.0.9-5.el6.centos.i686.rpm
libreport-plugin-logger libreport-plugin-logger-2.0.9-5.el6.centos.x86_64.rpm
libreport-plugin-mailx libreport-plugin-mailx-2.0.9-5.el6.centos.i686.rpm
libreport-plugin-mailx libreport-plugin-mailx-2.0.9-5.el6.centos.x86_64.rpm
libreport-plugin-reportuploader libreport-plugin-reportuploader-2.0.9-5.el6.centos.i686.rpm
libreport-plugin-reportuploader libreport-plugin-reportuploader-2.0.9-5.el6.centos.x86_64.rpm
libreport-plugin-rhtsupport libreport-plugin-rhtsupport-2.0.9-5.el6.centos.i686.rpm
libreport-plugin-rhtsupport libreport-plugin-rhtsupport-2.0.9-5.el6.centos.x86_64.rpm
libreport-python libreport-python-2.0.9-5.el6.centos.i686.rpm
libreport-python libreport-python-2.0.9-5.el6.centos.x86_64.rpm