Moderate CentOS libreport Security Update

Metadata

medium
5.0
libreport-2.0.9-25.el6.centos.i686.rpm, libreport-2.0.9-25.el6.centos.src.rpm, libreport-2.0.9-25.el6.centos.x86_64.rpm, libreport-cli-2.0.9-25.el6.centos.i686.rpm, libreport-cli-2.0.9-25.el6.centos.x86_64.rpm, libreport-compat-2.0.9-25.el6.centos.i686.rpm, libreport-compat-2.0.9-25.el6.centos.x86_64.rpm, libreport-devel-2.0.9-25.el6.centos.i686.rpm, libreport-devel-2.0.9-25.el6.centos.x86_64.rpm, libreport-filesystem-2.0.9-25.el6.centos.i686.rpm, libreport-filesystem-2.0.9-25.el6.centos.x86_64.rpm, libreport-gtk-2.0.9-25.el6.centos.i686.rpm, libreport-gtk-2.0.9-25.el6.centos.x86_64.rpm, libreport-gtk-devel-2.0.9-25.el6.centos.i686.rpm, libreport-gtk-devel-2.0.9-25.el6.centos.x86_64.rpm, libreport-newt-2.0.9-25.el6.centos.i686.rpm, libreport-newt-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-bugzilla-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-bugzilla-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-kerneloops-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-kerneloops-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-logger-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-logger-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-mailx-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-mailx-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-reportuploader-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-reportuploader-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-rhtsupport-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-rhtsupport-2.0.9-25.el6.centos.x86_64.rpm, libreport-plugin-ureport-2.0.9-25.el6.centos.i686.rpm, libreport-plugin-ureport-2.0.9-25.el6.centos.x86_64.rpm, libreport-python-2.0.9-25.el6.centos.i686.rpm, libreport-python-2.0.9-25.el6.centos.x86_64.rpm
CVE-2015-5302
rhn.redhat.com, lists.centos.org
2015-12-02
2017-07-27 19:10
Moderate CentOS abrt Security Update
2017-04-01 19:09
2017-01-05 20:13

Description


Updated libreport packages that fix one security issue are now available
for Red Hat Enterprise Linux 6.

Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.

libreport provides an API for reporting different problems in applications
to different bug targets, such as Bugzilla, FTP, and Trac. ABRT (Automatic
Bug Reporting Tool) uses libreport.

It was found that ABRT may have exposed unintended information to Red Hat
Bugzilla during crash reporting. A bug in the libreport library caused
changes made by a user in files included in a crash report to be discarded.
As a result, Red Hat Bugzilla attachments may contain data that was not
intended to be made public, including host names, IP addresses, or command
line options. (CVE-2015-5302)

This flaw did not affect default installations of ABRT on Red Hat
Enterprise Linux as they do not post data to Red Hat Bugzilla. This feature
can however be enabled, potentially impacting modified ABRT instances.

As a precaution, Red Hat has identified bugs filed by such non-default Red
Hat Enterprise Linux users of ABRT and marked them private.

This issue was discovered by Bastien Nocera of Red Hat.

All users of libreport are advised to upgrade to these updated packages,
which corrects this issue.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
6 libreport libreport-2.0.9-25.el6.centos.i686.rpm
libreport libreport-2.0.9-25.el6.centos.src.rpm
libreport libreport-2.0.9-25.el6.centos.x86_64.rpm
libreport-cli libreport-cli-2.0.9-25.el6.centos.i686.rpm
libreport-cli libreport-cli-2.0.9-25.el6.centos.x86_64.rpm
libreport-compat libreport-compat-2.0.9-25.el6.centos.i686.rpm
libreport-compat libreport-compat-2.0.9-25.el6.centos.x86_64.rpm
libreport-devel libreport-devel-2.0.9-25.el6.centos.i686.rpm
libreport-devel libreport-devel-2.0.9-25.el6.centos.x86_64.rpm
libreport-filesystem libreport-filesystem-2.0.9-25.el6.centos.i686.rpm
libreport-filesystem libreport-filesystem-2.0.9-25.el6.centos.x86_64.rpm
libreport-gtk libreport-gtk-2.0.9-25.el6.centos.i686.rpm
libreport-gtk libreport-gtk-2.0.9-25.el6.centos.x86_64.rpm
libreport-gtk-devel libreport-gtk-devel-2.0.9-25.el6.centos.i686.rpm
libreport-gtk-devel libreport-gtk-devel-2.0.9-25.el6.centos.x86_64.rpm
libreport-newt libreport-newt-2.0.9-25.el6.centos.i686.rpm
libreport-newt libreport-newt-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-bugzilla libreport-plugin-bugzilla-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-bugzilla libreport-plugin-bugzilla-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-kerneloops libreport-plugin-kerneloops-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-kerneloops libreport-plugin-kerneloops-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-logger libreport-plugin-logger-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-logger libreport-plugin-logger-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-mailx libreport-plugin-mailx-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-mailx libreport-plugin-mailx-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-reportuploader libreport-plugin-reportuploader-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-reportuploader libreport-plugin-reportuploader-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-rhtsupport libreport-plugin-rhtsupport-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-rhtsupport libreport-plugin-rhtsupport-2.0.9-25.el6.centos.x86_64.rpm
libreport-plugin-ureport libreport-plugin-ureport-2.0.9-25.el6.centos.i686.rpm
libreport-plugin-ureport libreport-plugin-ureport-2.0.9-25.el6.centos.x86_64.rpm
libreport-python libreport-python-2.0.9-25.el6.centos.i686.rpm
libreport-python libreport-python-2.0.9-25.el6.centos.x86_64.rpm