Moderate: abrt and libreport security update. Date: Mon, 21 Dec 2015 23:16:40 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: abrt and libreport on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: abrt and libreport security update Advisory ID: SLSA-2015:2505-1 Issue Date: 2015-11-23 CVE Numbers: CVE-2015-5302 CVE-2015-5273 CVE-2015-5287 -- It was found that the ABRT debug information installer (abrt-action- install-debuginfo-to-abrt-cache) did not use temporary directories in a secure way. A local attacker could use the flaw to create symbolic links and files at arbitrary locations as the abrt user. (CVE-2015-5273) It was discovered that the kernel-invoked coredump processor provided by ABRT did not handle symbolic links correctly when writing core dumps of ABRT programs to the ABRT dump directory (/var/spool/abrt). A local attacker with write access to an ABRT problem directory could use this flaw to escalate their privileges. (CVE-2015-5287) It was found that ABRT may have exposed unintended information to Red Hat Bugzilla during crash reporting. A bug in the libreport library caused changes made by a user in files included in a crash report to be discarded. As a result, Red Hat Bugzilla attachments may contain data that was not intended to be made public, including host names, IP addresses, or command line options. (CVE-2015-5302) This flaw did not affect default installations of ABRT on Scientific Linux as they do not post data to Red Hat Bugzilla. This feature can however be enabled, potentially impacting modified ABRT instances. With this update Scientific Linux will no longer publish the rhel-autoreport tools. -- SL7 x86_64 abrt-2.1.11-35.el7.x86_64.rpm abrt-addon-ccpp-2.1.11-35.el7.x86_64.rpm abrt-addon-kerneloops-2.1.11-35.el7.x86_64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.x86_64.rpm abrt-addon-python-2.1.11-35.el7.x86_64.rpm abrt-addon-vmcore-2.1.11-35.el7.x86_64.rpm abrt-addon-xorg-2.1.11-35.el7.x86_64.rpm abrt-cli-2.1.11-35.el7.x86_64.rpm abrt-console-notification-2.1.11-35.el7.x86_64.rpm abrt-dbus-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-desktop-2.1.11-35.el7.x86_64.rpm abrt-gui-2.1.11-35.el7.x86_64.rpm abrt-gui-libs-2.1.11-35.el7.i686.rpm abrt-gui-libs-2.1.11-35.el7.x86_64.rpm abrt-libs-2.1.11-35.el7.i686.rpm abrt-libs-2.1.11-35.el7.x86_64.rpm abrt-python-2.1.11-35.el7.x86_64.rpm abrt-tui-2.1.11-35.el7.x86_64.rpm libreport-2.1.11-31.el7.i686.rpm libreport-2.1.11-31.el7.x86_64.rpm libreport-anaconda-2.1.11-31.el7.x86_64.rpm libreport-cli-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-filesystem-2.1.11-31.el7.x86_64.rpm libreport-gtk-2.1.11-31.el7.i686.rpm libreport-gtk-2.1.11-31.el7.x86_64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-plugin-mailx-2.1.11-31.el7.x86_64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.x86_64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.x86_64.rpm libreport-plugin-ureport-2.1.11-31.el7.x86_64.rpm libreport-python-2.1.11-31.el7.x86_64.rpm libreport-rhel-2.1.11-31.el7.x86_64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-2.1.11-31.el7.i686.rpm libreport-web-2.1.11-31.el7.x86_64.rpm abrt-addon-upload-watch-2.1.11-35.el7.x86_64.rpm abrt-devel-2.1.11-35.el7.i686.rpm abrt-devel-2.1.11-35.el7.x86_64.rpm abrt-gui-devel-2.1.11-35.el7.i686.rpm abrt-gui-devel-2.1.11-35.el7.x86_64.rpm abrt-retrace-client-2.1.11-35.el7.x86_64.rpm libreport-compat-2.1.11-31.el7.x86_64.rpm libreport-devel-2.1.11-31.el7.i686.rpm libreport-devel-2.1.11-31.el7.x86_64.rpm libreport-gtk-devel-2.1.11-31.el7.i686.rpm libreport-gtk-devel-2.1.11-31.el7.x86_64.rpm libreport-newt-2.1.11-31.el7.x86_64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.x86_64.rpm libreport-plugin-logger-2.1.11-31.el7.x86_64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-devel-2.1.11-31.el7.i686.rpm libreport-web-devel-2.1.11-31.el7.x86_64.rpm noarch abrt-python-doc-2.1.11-35.el7.noarch.rpm - Scientific Linux Development Team . Significant patch rollout for ABRT and libreport on Scientific Linux improves management of core dumps and mitigates information leakage.. ABRT Security Update, Scientific Linux Update, libreport Vulnerability. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2015-5302 abrt-2.3.0-12.fc21 - doc: fix default DumpLocation in abrt.conf man page - bodhi: fix typo in error messages - abrt- dump-xorg: support Xorg log backtraces prefixed by (EE libreport-2.3.0-10.fc21 - fix save users changes after reviewing dump dir files - Resolves CVE-2015-5302. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6542ab6d3a 2015-11-26 04:57:38.195310 -------------------------------------------------------------------------------- Name : libreport Product : Fedora 21 Version : 2.3.0 Release : 10.fc21 URL : https://github.com/abrt/abrt/wiki/ABRT-Project Summary : Generic library for reporting various problems Description : Libraries providing API for reporting different problems in applications to different bug targets like Bugzilla, ftp, trac, etc... -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5302 abrt-2.3.0-12.fc21 - doc: fix default DumpLocation in abrt.conf man page - bodhi: fix typo in error messages - abrt- dump-xorg: support Xorg log backtraces prefixed by (EE libreport-2.3.0-10.fc21 - fix save users changes after reviewing dump dir files - Resolves CVE-2015-5302 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1270903 - CVE-2015-5302 libreport: Possible private data leak in Bugzilla bugs opened by ABRT https://bugzilla.redhat.com/show_bug.cgi?id=1270903 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libreport' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Moderate: libreport security update. Date: Tue, 24 Nov 2015 16:28:47 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: libreport on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: libreport security update Advisory ID: SLSA-2015:2504-1 Issue Date: 2015-11-23 CVE Numbers: CVE-2015-5302 -- It was found that ABRT may have exposed unintended information to Red Hat Bugzilla during crash reporting. A bug in the libreport library caused changes made by a user in files included in a crash report to be discarded. As a result, Bugzilla attachments may contain data that was not intended to be made public, including host names, IP addresses, or command line options. (CVE-2015-5302) This flaw did not affect default installations of ABRT on Scientific Linux as they do not post data to Red Hat Bugzilla. -- SL6 x86_64 libreport-2.0.9-25.el6_7.i686.rpm libreport-2.0.9-25.el6_7.x86_64.rpm libreport-cli-2.0.9-25.el6_7.x86_64.rpm libreport-compat-2.0.9-25.el6_7.x86_64.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-filesystem-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.x86_64.rpm libreport-newt-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-logger-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-mailx-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-ureport-2.0.9-25.el6_7.x86_64.rpm libreport-python-2.0.9-25.el6_7.x86_64.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.x86_64.rpm i386 libreport-2.0.9-25.el6_7.i686.rpm libreport-cli-2.0.9-25.el6_7.i686.rpm libreport-compat-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-filesystem-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-newt-2.0.9-25.el6_7.i686.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.i686.rpm libreport-plugin-logger-2.0.9-25.el6_7.i686.rpm libreport-plugin-mailx-2.0.9-25.el6_7.i686.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.i686.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.i686.rpm libreport-plugin-ureport-2.0.9-25.el6_7.i686.rpm libreport-python-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.i686.rpm - Scientific Linux Development Team . Cautious security notice for libreport on Scientific Linux resolves potential data leakage concerns.. libreport update, Scientific Linux security, exposure risks. . Severity: Important. LinuxSecurity.com Team
Updated abrt and libreport packages that fix three security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: abrt and libreport security update Advisory ID: RHSA-2015:2505-01 Product: Red Hat Enterprise Linux Advisory URL: Issue date: 2015-11-23 CVE Names: CVE-2015-5273 CVE-2015-5287 CVE-2015-5302 ==================================================================== 1. Summary: Updated abrt and libreport packages that fix three security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect defects in applications and to create a bug report with all the information needed by a maintainer to fix it. It uses a plug-in system to extend its functionality. libreport provides an API for reporting different problems inapplications to different bug targets, such as Bugzilla, FTP, and Trac. It was found that the ABRT debug information installer (abrt-action-install-debuginfo-to-abrt-cache) did not use temporary directories in a secure way. A local attacker could use the flaw to create symbolic links and files at arbitrary locations as the abrt user. (CVE-2015-5273) It was discovered that the kernel-invoked coredump processor provided by ABRT did not handle symbolic links correctly when writing core dumps of ABRT programs to the ABRT dump directory (/var/spool/abrt). A local attacker with write access to an ABRT problem directory could use this flaw to escalate their privileges. (CVE-2015-5287) It was found that ABRT may have exposed unintended information to Red Hat Bugzilla during crash reporting. A bug in the libreport library caused changes made by a user in files included in a crash report to be discarded. As a result, Red Hat Bugzilla attachments may contain data that was not intended to be made public, including host names, IP addresses, or command line options. (CVE-2015-5302) This flaw did not affect default installations of ABRT on Red Hat Enterprise Linux as they do not post data to Red Hat Bugzilla. This feature can however be enabled, potentially impacting modified ABRT instances. As a precaution, Red Hat has identified bugs filed by such non-default Red Hat Enterprise Linux users of ABRT and marked them private. Red Hat would like to thank Philip Pettersson of Samsung for reporting the CVE-2015-5273 and CVE-2015-5287 issues. The CVE-2015-5302 issue was discovered by Bastien Nocera of Red Hat. All users of abrt and libreport are advised to upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1262252 -CVE-2015-5273 abrt: Insecure temporary directory usage in abrt-action-install-debuginfo-to-abrt-cache 1266837 - CVE-2015-5287 abrt: incorrect permissions on /var/spool/abrt 1270903 - CVE-2015-5302 libreport: Possible private data leak in Bugzilla bugs opened by ABRT 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: abrt-2.1.11-35.el7.src.rpm libreport-2.1.11-31.el7.src.rpm x86_64: abrt-2.1.11-35.el7.x86_64.rpm abrt-addon-ccpp-2.1.11-35.el7.x86_64.rpm abrt-addon-kerneloops-2.1.11-35.el7.x86_64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.x86_64.rpm abrt-addon-python-2.1.11-35.el7.x86_64.rpm abrt-addon-vmcore-2.1.11-35.el7.x86_64.rpm abrt-addon-xorg-2.1.11-35.el7.x86_64.rpm abrt-cli-2.1.11-35.el7.x86_64.rpm abrt-console-notification-2.1.11-35.el7.x86_64.rpm abrt-dbus-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-desktop-2.1.11-35.el7.x86_64.rpm abrt-gui-2.1.11-35.el7.x86_64.rpm abrt-gui-libs-2.1.11-35.el7.i686.rpm abrt-gui-libs-2.1.11-35.el7.x86_64.rpm abrt-libs-2.1.11-35.el7.i686.rpm abrt-libs-2.1.11-35.el7.x86_64.rpm abrt-python-2.1.11-35.el7.x86_64.rpm abrt-tui-2.1.11-35.el7.x86_64.rpm libreport-2.1.11-31.el7.i686.rpm libreport-2.1.11-31.el7.x86_64.rpm libreport-anaconda-2.1.11-31.el7.x86_64.rpm libreport-cli-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-filesystem-2.1.11-31.el7.x86_64.rpm libreport-gtk-2.1.11-31.el7.i686.rpm libreport-gtk-2.1.11-31.el7.x86_64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-plugin-mailx-2.1.11-31.el7.x86_64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.x86_64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.x86_64.rpm libreport-plugin-ureport-2.1.11-31.el7.x86_64.rpm libreport-python-2.1.11-31.el7.x86_64.rpm libreport-rhel-2.1.11-31.el7.x86_64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-2.1.11-31.el7.i686.rpm libreport-web-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise LinuxClient Optional (v. 7): noarch: abrt-python-doc-2.1.11-35.el7.noarch.rpm x86_64: abrt-addon-upload-watch-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-devel-2.1.11-35.el7.i686.rpm abrt-devel-2.1.11-35.el7.x86_64.rpm abrt-gui-devel-2.1.11-35.el7.i686.rpm abrt-gui-devel-2.1.11-35.el7.x86_64.rpm abrt-retrace-client-2.1.11-35.el7.x86_64.rpm libreport-compat-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-devel-2.1.11-31.el7.i686.rpm libreport-devel-2.1.11-31.el7.x86_64.rpm libreport-gtk-devel-2.1.11-31.el7.i686.rpm libreport-gtk-devel-2.1.11-31.el7.x86_64.rpm libreport-newt-2.1.11-31.el7.x86_64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.x86_64.rpm libreport-plugin-logger-2.1.11-31.el7.x86_64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-devel-2.1.11-31.el7.i686.rpm libreport-web-devel-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v.7): Source: abrt-2.1.11-35.el7.src.rpm libreport-2.1.11-31.el7.src.rpm x86_64: abrt-2.1.11-35.el7.x86_64.rpm abrt-addon-ccpp-2.1.11-35.el7.x86_64.rpm abrt-addon-kerneloops-2.1.11-35.el7.x86_64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.x86_64.rpm abrt-addon-python-2.1.11-35.el7.x86_64.rpm abrt-addon-vmcore-2.1.11-35.el7.x86_64.rpm abrt-addon-xorg-2.1.11-35.el7.x86_64.rpm abrt-cli-2.1.11-35.el7.x86_64.rpm abrt-console-notification-2.1.11-35.el7.x86_64.rpm abrt-dbus-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-libs-2.1.11-35.el7.i686.rpm abrt-libs-2.1.11-35.el7.x86_64.rpm abrt-python-2.1.11-35.el7.x86_64.rpm abrt-tui-2.1.11-35.el7.x86_64.rpm libreport-2.1.11-31.el7.i686.rpm libreport-2.1.11-31.el7.x86_64.rpm libreport-anaconda-2.1.11-31.el7.x86_64.rpm libreport-cli-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-filesystem-2.1.11-31.el7.x86_64.rpm libreport-gtk-2.1.11-31.el7.i686.rpm libreport-gtk-2.1.11-31.el7.x86_64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-plugin-mailx-2.1.11-31.el7.x86_64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.x86_64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.x86_64.rpm libreport-plugin-ureport-2.1.11-31.el7.x86_64.rpm libreport-python-2.1.11-31.el7.x86_64.rpm libreport-rhel-2.1.11-31.el7.x86_64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-2.1.11-31.el7.i686.rpm libreport-web-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): noarch: abrt-python-doc-2.1.11-35.el7.noarch.rpm x86_64: abrt-addon-upload-watch-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-desktop-2.1.11-35.el7.x86_64.rpm abrt-devel-2.1.11-35.el7.i686.rpm abrt-devel-2.1.11-35.el7.x86_64.rpm abrt-gui-2.1.11-35.el7.x86_64.rpm abrt-gui-devel-2.1.11-35.el7.i686.rpm abrt-gui-devel-2.1.11-35.el7.x86_64.rpm abrt-gui-libs-2.1.11-35.el7.i686.rpm abrt-gui-libs-2.1.11-35.el7.x86_64.rpm abrt-retrace-client-2.1.11-35.el7.x86_64.rpm libreport-compat-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-devel-2.1.11-31.el7.i686.rpm libreport-devel-2.1.11-31.el7.x86_64.rpm libreport-gtk-devel-2.1.11-31.el7.i686.rpm libreport-gtk-devel-2.1.11-31.el7.x86_64.rpm libreport-newt-2.1.11-31.el7.x86_64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.x86_64.rpm libreport-plugin-logger-2.1.11-31.el7.x86_64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-devel-2.1.11-31.el7.i686.rpm libreport-web-devel-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: abrt-2.1.11-35.el7.src.rpm libreport-2.1.11-31.el7.src.rpm aarch64: abrt-2.1.11-35.el7.aarch64.rpm abrt-addon-ccpp-2.1.11-35.el7.aarch64.rpm abrt-addon-kerneloops-2.1.11-35.el7.aarch64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.aarch64.rpm abrt-addon-python-2.1.11-35.el7.aarch64.rpm abrt-addon-vmcore-2.1.11-35.el7.aarch64.rpm abrt-addon-xorg-2.1.11-35.el7.aarch64.rpm abrt-cli-2.1.11-35.el7.aarch64.rpm abrt-console-notification-2.1.11-35.el7.aarch64.rpm abrt-dbus-2.1.11-35.el7.aarch64.rpm abrt-debuginfo-2.1.11-35.el7.aarch64.rpm abrt-desktop-2.1.11-35.el7.aarch64.rpm abrt-gui-2.1.11-35.el7.aarch64.rpm abrt-gui-libs-2.1.11-35.el7.aarch64.rpm abrt-libs-2.1.11-35.el7.aarch64.rpm abrt-python-2.1.11-35.el7.aarch64.rpm abrt-tui-2.1.11-35.el7.aarch64.rpm libreport-2.1.11-31.el7.aarch64.rpm libreport-anaconda-2.1.11-31.el7.aarch64.rpm libreport-cli-2.1.11-31.el7.aarch64.rpm libreport-debuginfo-2.1.11-31.el7.aarch64.rpm libreport-filesystem-2.1.11-31.el7.aarch64.rpm libreport-gtk-2.1.11-31.el7.aarch64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.aarch64.rpm libreport-plugin-mailx-2.1.11-31.el7.aarch64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.aarch64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.aarch64.rpm libreport-plugin-ureport-2.1.11-31.el7.aarch64.rpm libreport-python-2.1.11-31.el7.aarch64.rpm libreport-rhel-2.1.11-31.el7.aarch64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.aarch64.rpm libreport-web-2.1.11-31.el7.aarch64.rpm ppc64: abrt-2.1.11-35.el7.ppc64.rpm abrt-addon-ccpp-2.1.11-35.el7.ppc64.rpm abrt-addon-kerneloops-2.1.11-35.el7.ppc64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.ppc64.rpm abrt-addon-python-2.1.11-35.el7.ppc64.rpm abrt-addon-vmcore-2.1.11-35.el7.ppc64.rpm abrt-addon-xorg-2.1.11-35.el7.ppc64.rpm abrt-cli-2.1.11-35.el7.ppc64.rpm abrt-console-notification-2.1.11-35.el7.ppc64.rpm abrt-dbus-2.1.11-35.el7.ppc64.rpm abrt-debuginfo-2.1.11-35.el7.ppc.rpm abrt-debuginfo-2.1.11-35.el7.ppc64.rpm abrt-desktop-2.1.11-35.el7.ppc64.rpm abrt-gui-2.1.11-35.el7.ppc64.rpm abrt-gui-libs-2.1.11-35.el7.ppc.rpm abrt-gui-libs-2.1.11-35.el7.ppc64.rpm abrt-libs-2.1.11-35.el7.ppc.rpm abrt-libs-2.1.11-35.el7.ppc64.rpm abrt-python-2.1.11-35.el7.ppc64.rpm abrt-tui-2.1.11-35.el7.ppc64.rpm libreport-2.1.11-31.el7.ppc.rpm libreport-2.1.11-31.el7.ppc64.rpm libreport-anaconda-2.1.11-31.el7.ppc64.rpm libreport-cli-2.1.11-31.el7.ppc64.rpm libreport-debuginfo-2.1.11-31.el7.ppc.rpm libreport-debuginfo-2.1.11-31.el7.ppc64.rpm libreport-filesystem-2.1.11-31.el7.ppc64.rpm libreport-gtk-2.1.11-31.el7.ppc.rpm libreport-gtk-2.1.11-31.el7.ppc64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.ppc64.rpm libreport-plugin-mailx-2.1.11-31.el7.ppc64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.ppc64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.ppc64.rpm libreport-plugin-ureport-2.1.11-31.el7.ppc64.rpm libreport-python-2.1.11-31.el7.ppc64.rpm libreport-rhel-2.1.11-31.el7.ppc64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.ppc64.rpm libreport-web-2.1.11-31.el7.ppc.rpm libreport-web-2.1.11-31.el7.ppc64.rpm ppc64le: abrt-2.1.11-35.el7.ppc64le.rpm abrt-addon-ccpp-2.1.11-35.el7.ppc64le.rpm abrt-addon-kerneloops-2.1.11-35.el7.ppc64le.rpm abrt-addon-pstoreoops-2.1.11-35.el7.ppc64le.rpm abrt-addon-python-2.1.11-35.el7.ppc64le.rpm abrt-addon-vmcore-2.1.11-35.el7.ppc64le.rpm abrt-addon-xorg-2.1.11-35.el7.ppc64le.rpm abrt-cli-2.1.11-35.el7.ppc64le.rpm abrt-console-notification-2.1.11-35.el7.ppc64le.rpm abrt-dbus-2.1.11-35.el7.ppc64le.rpm abrt-debuginfo-2.1.11-35.el7.ppc64le.rpm abrt-desktop-2.1.11-35.el7.ppc64le.rpm abrt-gui-2.1.11-35.el7.ppc64le.rpm abrt-gui-libs-2.1.11-35.el7.ppc64le.rpm abrt-libs-2.1.11-35.el7.ppc64le.rpm abrt-python-2.1.11-35.el7.ppc64le.rpm abrt-tui-2.1.11-35.el7.ppc64le.rpm libreport-2.1.11-31.el7.ppc64le.rpm libreport-anaconda-2.1.11-31.el7.ppc64le.rpm libreport-cli-2.1.11-31.el7.ppc64le.rpm libreport-debuginfo-2.1.11-31.el7.ppc64le.rpm libreport-filesystem-2.1.11-31.el7.ppc64le.rpm libreport-gtk-2.1.11-31.el7.ppc64le.rpm libreport-plugin-bugzilla-2.1.11-31.el7.ppc64le.rpm libreport-plugin-mailx-2.1.11-31.el7.ppc64le.rpm libreport-plugin-reportuploader-2.1.11-31.el7.ppc64le.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.ppc64le.rpm libreport-plugin-ureport-2.1.11-31.el7.ppc64le.rpm libreport-python-2.1.11-31.el7.ppc64le.rpm libreport-rhel-2.1.11-31.el7.ppc64le.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.ppc64le.rpm libreport-web-2.1.11-31.el7.ppc64le.rpm s390x: abrt-2.1.11-35.el7.s390x.rpm abrt-addon-ccpp-2.1.11-35.el7.s390x.rpm abrt-addon-kerneloops-2.1.11-35.el7.s390x.rpm abrt-addon-pstoreoops-2.1.11-35.el7.s390x.rpm abrt-addon-python-2.1.11-35.el7.s390x.rpm abrt-addon-vmcore-2.1.11-35.el7.s390x.rpm abrt-addon-xorg-2.1.11-35.el7.s390x.rpm abrt-cli-2.1.11-35.el7.s390x.rpm abrt-console-notification-2.1.11-35.el7.s390x.rpm abrt-dbus-2.1.11-35.el7.s390x.rpm abrt-debuginfo-2.1.11-35.el7.s390.rpm abrt-debuginfo-2.1.11-35.el7.s390x.rpm abrt-desktop-2.1.11-35.el7.s390x.rpm abrt-gui-2.1.11-35.el7.s390x.rpm abrt-gui-libs-2.1.11-35.el7.s390.rpm abrt-gui-libs-2.1.11-35.el7.s390x.rpm abrt-libs-2.1.11-35.el7.s390.rpm abrt-libs-2.1.11-35.el7.s390x.rpm abrt-python-2.1.11-35.el7.s390x.rpm abrt-tui-2.1.11-35.el7.s390x.rpm libreport-2.1.11-31.el7.s390.rpm libreport-2.1.11-31.el7.s390x.rpm libreport-anaconda-2.1.11-31.el7.s390x.rpm libreport-cli-2.1.11-31.el7.s390x.rpm libreport-debuginfo-2.1.11-31.el7.s390.rpm libreport-debuginfo-2.1.11-31.el7.s390x.rpm libreport-filesystem-2.1.11-31.el7.s390x.rpm libreport-gtk-2.1.11-31.el7.s390.rpm libreport-gtk-2.1.11-31.el7.s390x.rpm libreport-plugin-bugzilla-2.1.11-31.el7.s390x.rpm libreport-plugin-mailx-2.1.11-31.el7.s390x.rpm libreport-plugin-reportuploader-2.1.11-31.el7.s390x.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.s390x.rpm libreport-plugin-ureport-2.1.11-31.el7.s390x.rpm libreport-python-2.1.11-31.el7.s390x.rpm libreport-rhel-2.1.11-31.el7.s390x.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.s390x.rpm libreport-web-2.1.11-31.el7.s390.rpm libreport-web-2.1.11-31.el7.s390x.rpm x86_64: abrt-2.1.11-35.el7.x86_64.rpm abrt-addon-ccpp-2.1.11-35.el7.x86_64.rpm abrt-addon-kerneloops-2.1.11-35.el7.x86_64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.x86_64.rpm abrt-addon-python-2.1.11-35.el7.x86_64.rpm abrt-addon-vmcore-2.1.11-35.el7.x86_64.rpm abrt-addon-xorg-2.1.11-35.el7.x86_64.rpm abrt-cli-2.1.11-35.el7.x86_64.rpm abrt-console-notification-2.1.11-35.el7.x86_64.rpm abrt-dbus-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-desktop-2.1.11-35.el7.x86_64.rpm abrt-gui-2.1.11-35.el7.x86_64.rpm abrt-gui-libs-2.1.11-35.el7.i686.rpm abrt-gui-libs-2.1.11-35.el7.x86_64.rpm abrt-libs-2.1.11-35.el7.i686.rpm abrt-libs-2.1.11-35.el7.x86_64.rpm abrt-python-2.1.11-35.el7.x86_64.rpm abrt-tui-2.1.11-35.el7.x86_64.rpm libreport-2.1.11-31.el7.i686.rpm libreport-2.1.11-31.el7.x86_64.rpm libreport-anaconda-2.1.11-31.el7.x86_64.rpm libreport-cli-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-filesystem-2.1.11-31.el7.x86_64.rpm libreport-gtk-2.1.11-31.el7.i686.rpm libreport-gtk-2.1.11-31.el7.x86_64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-plugin-mailx-2.1.11-31.el7.x86_64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.x86_64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.x86_64.rpm libreport-plugin-ureport-2.1.11-31.el7.x86_64.rpm libreport-python-2.1.11-31.el7.x86_64.rpm libreport-rhel-2.1.11-31.el7.x86_64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-2.1.11-31.el7.i686.rpm libreport-web-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): aarch64: abrt-addon-upload-watch-2.1.11-35.el7.aarch64.rpm abrt-debuginfo-2.1.11-35.el7.aarch64.rpm abrt-devel-2.1.11-35.el7.aarch64.rpm abrt-gui-devel-2.1.11-35.el7.aarch64.rpm abrt-retrace-client-2.1.11-35.el7.aarch64.rpm libreport-compat-2.1.11-31.el7.aarch64.rpm libreport-debuginfo-2.1.11-31.el7.aarch64.rpm libreport-devel-2.1.11-31.el7.aarch64.rpm libreport-gtk-devel-2.1.11-31.el7.aarch64.rpm libreport-newt-2.1.11-31.el7.aarch64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.aarch64.rpm libreport-plugin-logger-2.1.11-31.el7.aarch64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.aarch64.rpm libreport-web-devel-2.1.11-31.el7.aarch64.rpm noarch: abrt-python-doc-2.1.11-35.el7.noarch.rpm ppc64: abrt-addon-upload-watch-2.1.11-35.el7.ppc64.rpm abrt-debuginfo-2.1.11-35.el7.ppc.rpm abrt-debuginfo-2.1.11-35.el7.ppc64.rpm abrt-devel-2.1.11-35.el7.ppc.rpm abrt-devel-2.1.11-35.el7.ppc64.rpm abrt-gui-devel-2.1.11-35.el7.ppc.rpm abrt-gui-devel-2.1.11-35.el7.ppc64.rpm abrt-retrace-client-2.1.11-35.el7.ppc64.rpm libreport-compat-2.1.11-31.el7.ppc64.rpm libreport-debuginfo-2.1.11-31.el7.ppc.rpm libreport-debuginfo-2.1.11-31.el7.ppc64.rpm libreport-devel-2.1.11-31.el7.ppc.rpm libreport-devel-2.1.11-31.el7.ppc64.rpm libreport-gtk-devel-2.1.11-31.el7.ppc.rpm libreport-gtk-devel-2.1.11-31.el7.ppc64.rpm libreport-newt-2.1.11-31.el7.ppc64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.ppc64.rpm libreport-plugin-logger-2.1.11-31.el7.ppc64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.ppc64.rpm libreport-web-devel-2.1.11-31.el7.ppc.rpm libreport-web-devel-2.1.11-31.el7.ppc64.rpm ppc64le: abrt-addon-upload-watch-2.1.11-35.el7.ppc64le.rpm abrt-debuginfo-2.1.11-35.el7.ppc64le.rpm abrt-devel-2.1.11-35.el7.ppc64le.rpm abrt-gui-devel-2.1.11-35.el7.ppc64le.rpm abrt-retrace-client-2.1.11-35.el7.ppc64le.rpm libreport-compat-2.1.11-31.el7.ppc64le.rpm libreport-debuginfo-2.1.11-31.el7.ppc64le.rpm libreport-devel-2.1.11-31.el7.ppc64le.rpm libreport-gtk-devel-2.1.11-31.el7.ppc64le.rpm libreport-newt-2.1.11-31.el7.ppc64le.rpm libreport-plugin-kerneloops-2.1.11-31.el7.ppc64le.rpm libreport-plugin-logger-2.1.11-31.el7.ppc64le.rpm libreport-rhel-bugzilla-2.1.11-31.el7.ppc64le.rpm libreport-web-devel-2.1.11-31.el7.ppc64le.rpm s390x: abrt-addon-upload-watch-2.1.11-35.el7.s390x.rpm abrt-debuginfo-2.1.11-35.el7.s390.rpm abrt-debuginfo-2.1.11-35.el7.s390x.rpm abrt-devel-2.1.11-35.el7.s390.rpm abrt-devel-2.1.11-35.el7.s390x.rpm abrt-gui-devel-2.1.11-35.el7.s390.rpm abrt-gui-devel-2.1.11-35.el7.s390x.rpm abrt-retrace-client-2.1.11-35.el7.s390x.rpm libreport-compat-2.1.11-31.el7.s390x.rpm libreport-debuginfo-2.1.11-31.el7.s390.rpm libreport-debuginfo-2.1.11-31.el7.s390x.rpm libreport-devel-2.1.11-31.el7.s390.rpm libreport-devel-2.1.11-31.el7.s390x.rpm libreport-gtk-devel-2.1.11-31.el7.s390.rpm libreport-gtk-devel-2.1.11-31.el7.s390x.rpm libreport-newt-2.1.11-31.el7.s390x.rpm libreport-plugin-kerneloops-2.1.11-31.el7.s390x.rpm libreport-plugin-logger-2.1.11-31.el7.s390x.rpm libreport-rhel-bugzilla-2.1.11-31.el7.s390x.rpm libreport-web-devel-2.1.11-31.el7.s390.rpm libreport-web-devel-2.1.11-31.el7.s390x.rpm x86_64: abrt-addon-upload-watch-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-devel-2.1.11-35.el7.i686.rpm abrt-devel-2.1.11-35.el7.x86_64.rpm abrt-gui-devel-2.1.11-35.el7.i686.rpm abrt-gui-devel-2.1.11-35.el7.x86_64.rpm abrt-retrace-client-2.1.11-35.el7.x86_64.rpm libreport-compat-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-devel-2.1.11-31.el7.i686.rpm libreport-devel-2.1.11-31.el7.x86_64.rpm libreport-gtk-devel-2.1.11-31.el7.i686.rpm libreport-gtk-devel-2.1.11-31.el7.x86_64.rpm libreport-newt-2.1.11-31.el7.x86_64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.x86_64.rpm libreport-plugin-logger-2.1.11-31.el7.x86_64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-devel-2.1.11-31.el7.i686.rpm libreport-web-devel-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: abrt-2.1.11-35.el7.src.rpm libreport-2.1.11-31.el7.src.rpm x86_64: abrt-2.1.11-35.el7.x86_64.rpm abrt-addon-ccpp-2.1.11-35.el7.x86_64.rpm abrt-addon-kerneloops-2.1.11-35.el7.x86_64.rpm abrt-addon-pstoreoops-2.1.11-35.el7.x86_64.rpm abrt-addon-python-2.1.11-35.el7.x86_64.rpm abrt-addon-vmcore-2.1.11-35.el7.x86_64.rpm abrt-addon-xorg-2.1.11-35.el7.x86_64.rpm abrt-cli-2.1.11-35.el7.x86_64.rpm abrt-console-notification-2.1.11-35.el7.x86_64.rpm abrt-dbus-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-desktop-2.1.11-35.el7.x86_64.rpm abrt-gui-2.1.11-35.el7.x86_64.rpm abrt-gui-libs-2.1.11-35.el7.i686.rpm abrt-gui-libs-2.1.11-35.el7.x86_64.rpm abrt-libs-2.1.11-35.el7.i686.rpm abrt-libs-2.1.11-35.el7.x86_64.rpm abrt-python-2.1.11-35.el7.x86_64.rpm abrt-tui-2.1.11-35.el7.x86_64.rpm libreport-2.1.11-31.el7.i686.rpm libreport-2.1.11-31.el7.x86_64.rpm libreport-anaconda-2.1.11-31.el7.x86_64.rpm libreport-cli-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-filesystem-2.1.11-31.el7.x86_64.rpm libreport-gtk-2.1.11-31.el7.i686.rpm libreport-gtk-2.1.11-31.el7.x86_64.rpm libreport-plugin-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-plugin-mailx-2.1.11-31.el7.x86_64.rpm libreport-plugin-reportuploader-2.1.11-31.el7.x86_64.rpm libreport-plugin-rhtsupport-2.1.11-31.el7.x86_64.rpm libreport-plugin-ureport-2.1.11-31.el7.x86_64.rpm libreport-python-2.1.11-31.el7.x86_64.rpm libreport-rhel-2.1.11-31.el7.x86_64.rpm libreport-rhel-anaconda-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-2.1.11-31.el7.i686.rpm libreport-web-2.1.11-31.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): noarch: abrt-python-doc-2.1.11-35.el7.noarch.rpm x86_64: abrt-addon-upload-watch-2.1.11-35.el7.x86_64.rpm abrt-debuginfo-2.1.11-35.el7.i686.rpm abrt-debuginfo-2.1.11-35.el7.x86_64.rpm abrt-devel-2.1.11-35.el7.i686.rpm abrt-devel-2.1.11-35.el7.x86_64.rpm abrt-gui-devel-2.1.11-35.el7.i686.rpm abrt-gui-devel-2.1.11-35.el7.x86_64.rpm abrt-retrace-client-2.1.11-35.el7.x86_64.rpm libreport-compat-2.1.11-31.el7.x86_64.rpm libreport-debuginfo-2.1.11-31.el7.i686.rpm libreport-debuginfo-2.1.11-31.el7.x86_64.rpm libreport-devel-2.1.11-31.el7.i686.rpm libreport-devel-2.1.11-31.el7.x86_64.rpm libreport-gtk-devel-2.1.11-31.el7.i686.rpm libreport-gtk-devel-2.1.11-31.el7.x86_64.rpm libreport-newt-2.1.11-31.el7.x86_64.rpm libreport-plugin-kerneloops-2.1.11-31.el7.x86_64.rpm libreport-plugin-logger-2.1.11-31.el7.x86_64.rpm libreport-rhel-bugzilla-2.1.11-31.el7.x86_64.rpm libreport-web-devel-2.1.11-31.el7.i686.rpm libreport-web-devel-2.1.11-31.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-5273 https://access.redhat.com/security/cve/CVE-2015-5287 https://access.redhat.com/security/cve/CVE-2015-5302 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWUyNqXlSAg2UNWIIRAtmJAJ9qTu+xj8J+qReBtx65aDeMJ9x00wCcDO0e UVHcRLkw43goN46qI7AdciQ=9fL0 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated libreport packages that fix one security issue are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libreport security update Advisory ID: RHSA-2015:2504-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:2504.html Issue date: 2015-11-23 CVE Names: CVE-2015-5302 ==================================================================== 1. Summary: Updated libreport packages that fix one security issue are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: libreport provides an API for reporting different problems in applications to different bug targets, such as Bugzilla, FTP, and Trac. ABRT (Automatic Bug Reporting Tool) uses libreport. It was found that ABRT may have exposed unintended information to Red Hat Bugzilla during crash reporting. A bug in the libreport library caused changes made by a user in files included in acrash report to be discarded. As a result, Red Hat Bugzilla attachments may contain data that was not intended to be made public, including host names, IP addresses, or command line options. (CVE-2015-5302) This flaw did not affect default installations of ABRT on Red Hat Enterprise Linux as they do not post data to Red Hat Bugzilla. This feature can however be enabled, potentially impacting modified ABRT instances. As a precaution, Red Hat has identified bugs filed by such non-default Red Hat Enterprise Linux users of ABRT and marked them private. This issue was discovered by Bastien Nocera of Red Hat. All users of libreport are advised to upgrade to these updated packages, which corrects this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1270903 - CVE-2015-5302 libreport: Possible private data leak in Bugzilla bugs opened by ABRT 6. Package List: Red Hat Enterprise Linux Desktop (v.6): Source: libreport-2.0.9-25.el6_7.src.rpm i386: libreport-2.0.9-25.el6_7.i686.rpm libreport-cli-2.0.9-25.el6_7.i686.rpm libreport-compat-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-filesystem-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-newt-2.0.9-25.el6_7.i686.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.i686.rpm libreport-plugin-logger-2.0.9-25.el6_7.i686.rpm libreport-plugin-mailx-2.0.9-25.el6_7.i686.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.i686.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.i686.rpm libreport-plugin-ureport-2.0.9-25.el6_7.i686.rpm libreport-python-2.0.9-25.el6_7.i686.rpm x86_64: libreport-2.0.9-25.el6_7.i686.rpm libreport-2.0.9-25.el6_7.x86_64.rpm libreport-cli-2.0.9-25.el6_7.x86_64.rpm libreport-compat-2.0.9-25.el6_7.x86_64.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-filesystem-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.x86_64.rpm libreport-newt-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-logger-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-mailx-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-ureport-2.0.9-25.el6_7.x86_64.rpm libreport-python-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.i686.rpm x86_64: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux HPC Node(v. 6): Source: libreport-2.0.9-25.el6_7.src.rpm x86_64: libreport-2.0.9-25.el6_7.i686.rpm libreport-2.0.9-25.el6_7.x86_64.rpm libreport-cli-2.0.9-25.el6_7.x86_64.rpm libreport-compat-2.0.9-25.el6_7.x86_64.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-filesystem-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-logger-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-mailx-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-ureport-2.0.9-25.el6_7.x86_64.rpm libreport-python-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.x86_64.rpm libreport-newt-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: libreport-2.0.9-25.el6_7.src.rpm i386: libreport-2.0.9-25.el6_7.i686.rpm libreport-cli-2.0.9-25.el6_7.i686.rpm libreport-compat-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-filesystem-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-newt-2.0.9-25.el6_7.i686.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.i686.rpm libreport-plugin-logger-2.0.9-25.el6_7.i686.rpm libreport-plugin-mailx-2.0.9-25.el6_7.i686.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.i686.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.i686.rpm libreport-plugin-ureport-2.0.9-25.el6_7.i686.rpm libreport-python-2.0.9-25.el6_7.i686.rpm ppc64: libreport-2.0.9-25.el6_7.ppc.rpm libreport-2.0.9-25.el6_7.ppc64.rpm libreport-cli-2.0.9-25.el6_7.ppc64.rpm libreport-compat-2.0.9-25.el6_7.ppc64.rpm libreport-debuginfo-2.0.9-25.el6_7.ppc.rpm libreport-debuginfo-2.0.9-25.el6_7.ppc64.rpm libreport-filesystem-2.0.9-25.el6_7.ppc64.rpm libreport-gtk-2.0.9-25.el6_7.ppc.rpm libreport-gtk-2.0.9-25.el6_7.ppc64.rpm libreport-newt-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-logger-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-mailx-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-ureport-2.0.9-25.el6_7.ppc64.rpm libreport-python-2.0.9-25.el6_7.ppc64.rpm s390x: libreport-2.0.9-25.el6_7.s390.rpm libreport-2.0.9-25.el6_7.s390x.rpm libreport-cli-2.0.9-25.el6_7.s390x.rpm libreport-compat-2.0.9-25.el6_7.s390x.rpm libreport-debuginfo-2.0.9-25.el6_7.s390.rpm libreport-debuginfo-2.0.9-25.el6_7.s390x.rpm libreport-filesystem-2.0.9-25.el6_7.s390x.rpm libreport-gtk-2.0.9-25.el6_7.s390.rpm libreport-gtk-2.0.9-25.el6_7.s390x.rpm libreport-newt-2.0.9-25.el6_7.s390x.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.s390x.rpm libreport-plugin-logger-2.0.9-25.el6_7.s390x.rpm libreport-plugin-mailx-2.0.9-25.el6_7.s390x.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.s390x.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.s390x.rpm libreport-plugin-ureport-2.0.9-25.el6_7.s390x.rpm libreport-python-2.0.9-25.el6_7.s390x.rpm x86_64: libreport-2.0.9-25.el6_7.i686.rpm libreport-2.0.9-25.el6_7.x86_64.rpm libreport-cli-2.0.9-25.el6_7.x86_64.rpm libreport-compat-2.0.9-25.el6_7.x86_64.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-filesystem-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.x86_64.rpm libreport-newt-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-logger-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-mailx-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-ureport-2.0.9-25.el6_7.x86_64.rpm libreport-python-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): i386: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.i686.rpm ppc64: libreport-debuginfo-2.0.9-25.el6_7.ppc.rpm libreport-debuginfo-2.0.9-25.el6_7.ppc64.rpm libreport-devel-2.0.9-25.el6_7.ppc.rpm libreport-devel-2.0.9-25.el6_7.ppc64.rpm libreport-gtk-devel-2.0.9-25.el6_7.ppc.rpm libreport-gtk-devel-2.0.9-25.el6_7.ppc64.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.ppc64.rpm s390x: libreport-debuginfo-2.0.9-25.el6_7.s390.rpm libreport-debuginfo-2.0.9-25.el6_7.s390x.rpm libreport-devel-2.0.9-25.el6_7.s390.rpm libreport-devel-2.0.9-25.el6_7.s390x.rpm libreport-gtk-devel-2.0.9-25.el6_7.s390.rpm libreport-gtk-devel-2.0.9-25.el6_7.s390x.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.s390x.rpm x86_64: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: libreport-2.0.9-25.el6_7.src.rpm i386: libreport-2.0.9-25.el6_7.i686.rpm libreport-cli-2.0.9-25.el6_7.i686.rpm libreport-compat-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-filesystem-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-newt-2.0.9-25.el6_7.i686.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.i686.rpm libreport-plugin-logger-2.0.9-25.el6_7.i686.rpm libreport-plugin-mailx-2.0.9-25.el6_7.i686.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.i686.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.i686.rpm libreport-plugin-ureport-2.0.9-25.el6_7.i686.rpm libreport-python-2.0.9-25.el6_7.i686.rpm x86_64: libreport-2.0.9-25.el6_7.i686.rpm libreport-2.0.9-25.el6_7.x86_64.rpm libreport-cli-2.0.9-25.el6_7.x86_64.rpm libreport-compat-2.0.9-25.el6_7.x86_64.rpm libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-filesystem-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-2.0.9-25.el6_7.i686.rpm libreport-gtk-2.0.9-25.el6_7.x86_64.rpm libreport-newt-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-kerneloops-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-logger-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-mailx-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-reportuploader-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-rhtsupport-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-ureport-2.0.9-25.el6_7.x86_64.rpm libreport-python-2.0.9-25.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): i386: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.i686.rpm x86_64: libreport-debuginfo-2.0.9-25.el6_7.i686.rpm libreport-debuginfo-2.0.9-25.el6_7.x86_64.rpm libreport-devel-2.0.9-25.el6_7.i686.rpm libreport-devel-2.0.9-25.el6_7.x86_64.rpm libreport-gtk-devel-2.0.9-25.el6_7.i686.rpm libreport-gtk-devel-2.0.9-25.el6_7.x86_64.rpm libreport-plugin-bugzilla-2.0.9-25.el6_7.x86_64.rpm These packages are GPG signedby Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-5302 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWUuJGXlSAg2UNWIIRAhLoAJ0YjnSOU9hNHJplossw4z8RCPzyOwCfQJOp Et4OtPj39ApsqFuTEbFnIwA=WkI9 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Security fix for CVE-2015-5302 abrt-2.7.0-2.fc23 - Fix broken problem details in abrt-cli/gnome-abrt abrt-2.7.0-1.fc23 - cli-ng: initial - bodhi: introduce wrapper for 'reporter-bugzilla -h' and 'abrt-bodhi' - handle-event: remove obsolete workaround - remove 'not needed' code - doc: change /var/tmp/abrt to /var/spool/abrt - doc: fix default DumpLocation in abrt.conf man page - abrt-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-cc585b503f 2015-10-31 16:04:40.593977 -------------------------------------------------------------------------------- Name : libreport Product : Fedora 23 Version : 2.6.3 Release : 1.fc23 URL : https://abrt.readthedocs.io/en/latest/ Summary : Generic library for reporting various problems Description : Libraries providing API for reporting different problems in applications to different bug targets like Bugzilla, ftp, trac, etc... -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5302 abrt-2.7.0-2.fc23 - Fix broken problem details in abrt-cli/gnome-abrt abrt-2.7.0-1.fc23 - cli-ng: initial - bodhi: introduce wrapper for 'reporter-bugzilla -h' and 'abrt-bodhi' - handle-event: remove obsolete workaround - remove 'not needed' code - doc: change /var/tmp/abrt to /var/spool/abrt - doc: fix default DumpLocation in abrt.conf man page - abrt- dump-xorg: support Xorg log backtraces prefixed by (EE) - Resolves #1264739 libreport-2.6.3-1.fc23 - reporter-bugzilla: add parameter -p - fix save userschanges after reviewing dump dir files - bugzilla: don't attach build_ids - rewrite event rule parser - ureport: improve curl's error messages - curl: add posibility to use own Certificate Authority cert - Resolves #1270235, CVE-2015-5302 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1270903 - CVE-2015-5302 libreport: Possible private data leak in Bugzillabugs opened by ABRT https://bugzilla.redhat.com/show_bug.cgi?id=1270903 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libreport' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Security fix for CVE-2015-5302 abrt-2.6.1-6.fc22 - doc: fix default DumpLocation in abrt.conf man page - abrt-retrace-client: use atoll for _size conversion - a-a-a-ccpp-local don't delete build_ids - abrt-dump-xorg: support Xorg log backtraces prefixed by (EE - bodhi: fix typo in error messages libreport-2.6.3-1.fc22 - reporter-bugzilla: add parameter -p - fix save users. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-b81f7e1e86 2015-10-28 16:02:18.285008 -------------------------------------------------------------------------------- Name : libreport Product : Fedora 22 Version : 2.6.3 Release : 1.fc22 URL : https://abrt.readthedocs.io/en/latest/ Summary : Generic library for reporting various problems Description : Libraries providing API for reporting different problems in applications to different bug targets like Bugzilla, ftp, trac, etc... -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5302 abrt-2.6.1-6.fc22 - doc: fix default DumpLocation in abrt.conf man page - abrt-retrace-client: use atoll for _size conversion - a-a-a-ccpp-local don't delete build_ids - abrt-dump-xorg: support Xorg log backtraces prefixed by (EE - bodhi: fix typo in error messages libreport-2.6.3-1.fc22 - reporter-bugzilla: add parameter -p - fix save userschanges after reviewing dump dir files - bugzilla: don't attach build_ids - rewrite event rule parser - ureport: improve curl's error messages - curl: add posibility to use own Certificate Authority cert - Resolves CVE-2015-5302 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1270903 - CVE-2015-5302 libreport: Possible private data leak in Bugzilla bugs opened by ABRT https://bugzilla.redhat.com/show_bug.cgi?id=1270903 -------------------------------------------------------------------------------- This update can be installedwith the "yum" update program. Use su -c 'yum update libreport' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Security fixes for: * CVE-2015-3315 * CVE-2015-3142 * CVE-2015-1869 * CVE-2015-1870. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10193 2015-06-20 13:34:35 -------------------------------------------------------------------------------- Name : libreport Product : Fedora 21 Version : 2.3.0 Release : 8.fc21 URL : https://github.com/abrt/abrt/wiki/ABRT-Project Summary : Generic library for reporting various problems Description : Libraries providing API for reporting different problems in applications to different bug targets like Bugzilla, ftp, trac, etc... -------------------------------------------------------------------------------- Update Information: Security fixes for: * CVE-2015-3315 * CVE-2015-3142 * CVE-2015-1869 * CVE-2015-1870 * CVE-2015-3151 * CVE-2015-3150 * CVE-2015-3159 abrt: ====* Move the default dump location from /var/tmp/abrt to /var/spool/abrt * Use root for owner of all dump directories * Stop reading hs_error.log from /tmp * Don not save the system logs by default * Don not save dmesg if kernel.dmesg_restrict=1 libreport: =========* Harden the code against directory traversal, symbolic and hard link attacks * Fix a bug causing that the first value of AlwaysExcludedElements was ignored * Fix missing icon for the "Stop" button icon name * Improve development documentation * Translations updates gnome-abrt: ==========* Use DBus to get problem data for detail dialog * Fix an error introduced with the details on System page * Enabled the Details also for the System problems -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2015 Matej Habrnal 2.3.0-8 - introduce a new function ask_yes_no_save_result * Tue Jun 16 2015 Matej Habrnal 2.3.0-7 - harden the code against directory traversal, symbolic and hard link attacks - fix a bug causing that the first value of AlwaysExcludedElements was ignored - fixmissing icon for the "Stop" button icon name - switch the default dump dir mode to 0640 - fix races in dump directory handling code - improve development documentation - translations updates - Resolves #1213485, #1169774 * Tue Feb 24 2015 Matej Habrnal 2.3.0-6 - ignore (a|A)ccesib(ility|le) words - try to reduce false positive sensitive words - ureport: correct variable initializations - allow (semi)recursive locking - ignored words: add a few 'key' and 'access' words - Resolves: #1175720, #1180135 * Fri Nov 28 2014 Jakub Filak 2.3.0-5 - anaconda: filter out rootpw lines - highglit OpenStack related strings - ureport: do not bother user with the configuration window - Resolves: #1041558 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1214609 - CVE-2015-3150 abrt: abrt-dbus does not guard against crafted problem directory path arguments [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1214609 [ 2 ] Bug #1216975 - CVE-2015-3159 abrt: missing process environment sanitizaton in abrt-action-install-debuginfo-to-abrt-cache [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1216975 [ 3 ] Bug #1214452 - CVE-2015-3151 abrt: directory traversals in several D-Bus methods implemented by abrt-dbus [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1214452 [ 4 ] Bug #1212871 - CVE-2015-1870 abrt: default abrt event scripts lead to information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1212871 [ 5 ] Bug #1212821 - CVE-2015-3142 abrt: abrt-hook-ccpp writes core dumps to existing files owned by others [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1212821 [ 6 ] Bug #1213485 - Can't extract files from downloaded debuginfo package https://bugzilla.redhat.com/show_bug.cgi?id=1213485 [ 7 ] Bug #1169774 - failure to extract debuginfo https://bugzilla.redhat.com/show_bug.cgi?id=1169774 [ 8 ] Bug #1193656 - abrt-gui renders crash list white-on-whitewhen using dark theme https://bugzilla.redhat.com/show_bug.cgi?id=1193656 [ 9 ] Bug #986876 - RFE: Disallow core dump upload entirely https://bugzilla.redhat.com/show_bug.cgi?id=986876 [ 10 ] Bug #1212865 - CVE-2015-1869 abrt: default event scripts follow symbolic links [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1212865 [ 11 ] Bug #1218239 - CVE-2015-3315 abrt: Various race-conditions and symlink issues found in abrt [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1218239 [ 12 ] Bug #1179752 - undocumented options in abrt-cli https://bugzilla.redhat.com/show_bug.cgi?id=1179752 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libreport' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.