CVE-2015-3142

MEDIUM

Automatic Bug Reporting Tool - Info Disclosure

Title source: llm

Description

The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

Scores

CVSS v3 4.7
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
redhat/automatic_bug_reporting_tool < 2.1.11
n/a/n/a
Published Jun 26, 2017
Tracked Since Feb 18, 2026