Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Fedora: 2015-79c1758468 Critical: ABRT Process Crash Report Fix

fedora
Calendar Grey November 28, 2015
Scroller Fedora
Fedora 23 has released updates for abrt, addressing vulnerabilities associated with temporary directories and failures in process crash reporting.
- CVE-2015-5287: ignore crashes of abrt tools if DebugLevel = 0 - CVE-2015-5273: create own random temporary directory - make crashes of processes with locked memory not-reportable...

Summary

abrt is a tool to help users to detect defects in applications and

to create a bug report with all information needed by maintainer to fix it.

It uses plugin system to extend its functionality.

Update Information:

- CVE-2015-5287: ignore crashes of abrt tools if DebugLevel = 0 - CVE-2015-5273: create own random temporary directory - make crashes of processes with locked memory not-reportable - detect xorg backtraces from journald - fix the coredumpctl integration tool

Change Log

References


[ 1 ] Bug #1262252 - CVE-2015-5273 abrt: Insecure temporary directory usage in abrt-action-install-debuginfo-to-abrt-cache https://bugzilla.redhat.com/show_bug.cgi?id=1262252

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update abrt' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: abrt
Product: Fedora 23
Version: 2.7.1
Release: 1.fc23
Summary: Automatic bug detection and reporting tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.