Vulnerability Name: | CVE-2012-5660 (CCN-81847) | ||||||||||||||||
Assigned: | 2012-10-24 | ||||||||||||||||
Published: | 2013-01-30 | ||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||
Summary: | abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes." | ||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 6.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
6.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
5.7 Medium (REDHAT Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-426 | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-5660 Source: secalert@redhat.com Type: Exploit, Patch secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-57662 abrt Race Condition Local Privilege Escalation Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 887866 CVE-2012-5660 abrt: Race condition in abrt-action-install-debuginfo Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN abrt-directories-symlink(81847) Source: CCN Type: abrt Web page abrt | ||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |