Moderate CentOS abrt Security Update

Metadata

medium
6.9
abrt-2.1.11-36.el7.centos.src.rpm, abrt-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-ccpp-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-kerneloops-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-pstoreoops-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-python-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-upload-watch-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-vmcore-2.1.11-36.el7.centos.x86_64.rpm, abrt-addon-xorg-2.1.11-36.el7.centos.x86_64.rpm, abrt-cli-2.1.11-36.el7.centos.x86_64.rpm, abrt-console-notification-2.1.11-36.el7.centos.x86_64.rpm, abrt-dbus-2.1.11-36.el7.centos.x86_64.rpm, abrt-desktop-2.1.11-36.el7.centos.x86_64.rpm, abrt-devel-2.1.11-36.el7.centos.i686.rpm, abrt-devel-2.1.11-36.el7.centos.x86_64.rpm, abrt-gui-2.1.11-36.el7.centos.x86_64.rpm, abrt-gui-devel-2.1.11-36.el7.centos.i686.rpm, abrt-gui-devel-2.1.11-36.el7.centos.x86_64.rpm, abrt-gui-libs-2.1.11-36.el7.centos.i686.rpm, abrt-gui-libs-2.1.11-36.el7.centos.x86_64.rpm, abrt-libs-2.1.11-36.el7.centos.i686.rpm, abrt-libs-2.1.11-36.el7.centos.x86_64.rpm, abrt-python-2.1.11-36.el7.centos.x86_64.rpm, abrt-python-doc-2.1.11-36.el7.centos.noarch.rpm, abrt-retrace-client-2.1.11-36.el7.centos.x86_64.rpm, abrt-tui-2.1.11-36.el7.centos.x86_64.rpm, libreport-2.1.11-32.el7.centos.i686.rpm, libreport-2.1.11-32.el7.centos.src.rpm, libreport-2.1.11-32.el7.centos.x86_64.rpm, libreport-anaconda-2.1.11-32.el7.centos.x86_64.rpm, libreport-centos-2.1.11-32.el7.centos.x86_64.rpm, libreport-cli-2.1.11-32.el7.centos.x86_64.rpm, libreport-compat-2.1.11-32.el7.centos.x86_64.rpm, libreport-devel-2.1.11-32.el7.centos.i686.rpm, libreport-devel-2.1.11-32.el7.centos.x86_64.rpm, libreport-filesystem-2.1.11-32.el7.centos.x86_64.rpm, libreport-gtk-2.1.11-32.el7.centos.i686.rpm, libreport-gtk-2.1.11-32.el7.centos.x86_64.rpm, libreport-gtk-devel-2.1.11-32.el7.centos.i686.rpm, libreport-gtk-devel-2.1.11-32.el7.centos.x86_64.rpm, libreport-newt-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-bugzilla-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-kerneloops-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-logger-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-mailx-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-mantisbt-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-reportuploader-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-rhtsupport-2.1.11-32.el7.centos.x86_64.rpm, libreport-plugin-ureport-2.1.11-32.el7.centos.x86_64.rpm, libreport-python-2.1.11-32.el7.centos.x86_64.rpm, libreport-rhel-2.1.11-32.el7.centos.x86_64.rpm, libreport-rhel-anaconda-bugzilla-2.1.11-32.el7.centos.x86_64.rpm, libreport-rhel-bugzilla-2.1.11-32.el7.centos.x86_64.rpm, libreport-web-2.1.11-32.el7.centos.i686.rpm, libreport-web-2.1.11-32.el7.centos.x86_64.rpm, libreport-web-devel-2.1.11-32.el7.centos.i686.rpm, libreport-web-devel-2.1.11-32.el7.centos.x86_64.rpm
CVE-2015-5273, CVE-2015-5287, CVE-2015-5302
rhn.redhat.com, lists.centos.org, lists.centos.org
2015-12-01
2017-07-27 19:10
Moderate CentOS libreport Security Update
2017-07-05 09:03
2017-04-01 19:09
2017-01-05 20:13

Description


Updated abrt and libreport packages that fix three security issues are now
available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.

ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect
defects in applications and to create a bug report with all the information
needed by a maintainer to fix it. It uses a plug-in system to extend its
functionality. libreport provides an API for reporting different problems
in applications to different bug targets, such as Bugzilla, FTP, and Trac.

It was found that the ABRT debug information installer
(abrt-action-install-debuginfo-to-abrt-cache) did not use temporary
directories in a secure way. A local attacker could use the flaw to create
symbolic links and files at arbitrary locations as the abrt user.
(CVE-2015-5273)

It was discovered that the kernel-invoked coredump processor provided by
ABRT did not handle symbolic links correctly when writing core dumps of
ABRT programs to the ABRT dump directory (/var/spool/abrt). A local
attacker with write access to an ABRT problem directory could use this flaw
to escalate their privileges. (CVE-2015-5287)

It was found that ABRT may have exposed unintended information to Red Hat
Bugzilla during crash reporting. A bug in the libreport library caused
changes made by a user in files included in a crash report to be discarded.
As a result, Red Hat Bugzilla attachments may contain data that was not
intended to be made public, including host names, IP addresses, or command
line options. (CVE-2015-5302)

This flaw did not affect default installations of ABRT on Red Hat
Enterprise Linux as they do not post data to Red Hat Bugzilla. This feature
can however be enabled, potentially impacting modified ABRT instances.

As a precaution, Red Hat has identified bugs filed by such non-default Red
Hat Enterprise Linux users of ABRT and marked them private.

Red Hat would like to thank Philip Pettersson of Samsung for reporting the
CVE-2015-5273 and CVE-2015-5287 issues. The CVE-2015-5302 issue was
discovered by Bastien Nocera of Red Hat.

All users of abrt and libreport are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
7 abrt abrt-2.1.11-36.el7.centos.src.rpm
abrt abrt-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-ccpp abrt-addon-ccpp-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-kerneloops abrt-addon-kerneloops-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-pstoreoops abrt-addon-pstoreoops-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-python abrt-addon-python-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-upload-watch abrt-addon-upload-watch-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-vmcore abrt-addon-vmcore-2.1.11-36.el7.centos.x86_64.rpm
abrt-addon-xorg abrt-addon-xorg-2.1.11-36.el7.centos.x86_64.rpm
abrt-cli abrt-cli-2.1.11-36.el7.centos.x86_64.rpm
abrt-console-notification abrt-console-notification-2.1.11-36.el7.centos.x86_64.rpm
abrt-dbus abrt-dbus-2.1.11-36.el7.centos.x86_64.rpm
abrt-desktop abrt-desktop-2.1.11-36.el7.centos.x86_64.rpm
abrt-devel abrt-devel-2.1.11-36.el7.centos.i686.rpm
abrt-devel abrt-devel-2.1.11-36.el7.centos.x86_64.rpm
abrt-gui abrt-gui-2.1.11-36.el7.centos.x86_64.rpm
abrt-gui-devel abrt-gui-devel-2.1.11-36.el7.centos.i686.rpm
abrt-gui-devel abrt-gui-devel-2.1.11-36.el7.centos.x86_64.rpm
abrt-gui-libs abrt-gui-libs-2.1.11-36.el7.centos.i686.rpm
abrt-gui-libs abrt-gui-libs-2.1.11-36.el7.centos.x86_64.rpm
abrt-libs abrt-libs-2.1.11-36.el7.centos.i686.rpm
abrt-libs abrt-libs-2.1.11-36.el7.centos.x86_64.rpm
abrt-python abrt-python-2.1.11-36.el7.centos.x86_64.rpm
abrt-python-doc abrt-python-doc-2.1.11-36.el7.centos.noarch.rpm
abrt-retrace-client abrt-retrace-client-2.1.11-36.el7.centos.x86_64.rpm
abrt-tui abrt-tui-2.1.11-36.el7.centos.x86_64.rpm
libreport libreport-2.1.11-32.el7.centos.i686.rpm
libreport libreport-2.1.11-32.el7.centos.src.rpm
libreport libreport-2.1.11-32.el7.centos.x86_64.rpm
libreport-anaconda libreport-anaconda-2.1.11-32.el7.centos.x86_64.rpm
libreport-centos libreport-centos-2.1.11-32.el7.centos.x86_64.rpm
libreport-cli libreport-cli-2.1.11-32.el7.centos.x86_64.rpm
libreport-compat libreport-compat-2.1.11-32.el7.centos.x86_64.rpm
libreport-devel libreport-devel-2.1.11-32.el7.centos.i686.rpm
libreport-devel libreport-devel-2.1.11-32.el7.centos.x86_64.rpm
libreport-filesystem libreport-filesystem-2.1.11-32.el7.centos.x86_64.rpm
libreport-gtk libreport-gtk-2.1.11-32.el7.centos.i686.rpm
libreport-gtk libreport-gtk-2.1.11-32.el7.centos.x86_64.rpm
libreport-gtk-devel libreport-gtk-devel-2.1.11-32.el7.centos.i686.rpm
libreport-gtk-devel libreport-gtk-devel-2.1.11-32.el7.centos.x86_64.rpm
libreport-newt libreport-newt-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-bugzilla libreport-plugin-bugzilla-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-kerneloops libreport-plugin-kerneloops-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-logger libreport-plugin-logger-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-mailx libreport-plugin-mailx-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-mantisbt libreport-plugin-mantisbt-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-reportuploader libreport-plugin-reportuploader-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-rhtsupport libreport-plugin-rhtsupport-2.1.11-32.el7.centos.x86_64.rpm
libreport-plugin-ureport libreport-plugin-ureport-2.1.11-32.el7.centos.x86_64.rpm
libreport-python libreport-python-2.1.11-32.el7.centos.x86_64.rpm
libreport-rhel libreport-rhel-2.1.11-32.el7.centos.x86_64.rpm
libreport-rhel-anaconda-bugzilla libreport-rhel-anaconda-bugzilla-2.1.11-32.el7.centos.x86_64.rpm
libreport-rhel-bugzilla libreport-rhel-bugzilla-2.1.11-32.el7.centos.x86_64.rpm
libreport-web libreport-web-2.1.11-32.el7.centos.i686.rpm
libreport-web libreport-web-2.1.11-32.el7.centos.x86_64.rpm
libreport-web-devel libreport-web-devel-2.1.11-32.el7.centos.i686.rpm
libreport-web-devel libreport-web-devel-2.1.11-32.el7.centos.x86_64.rpm