Upstream information
CVE-2015-5302 at MITRE
Description
libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| National Vulnerability Database |
Base Score | 5 |
Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
No SUSE Bugzilla entries cross referenced.
No SUSE Security Announcements cross referenced.
List of released packages
Product(s) | Fixed package version(s) | References |
SUSE Liberty Linux 7 | abrt >= 2.1.11-35.el7
abrt-addon-ccpp >= 2.1.11-35.el7
abrt-addon-kerneloops >= 2.1.11-35.el7
abrt-addon-pstoreoops >= 2.1.11-35.el7
abrt-addon-python >= 2.1.11-35.el7
abrt-addon-upload-watch >= 2.1.11-35.el7
abrt-addon-vmcore >= 2.1.11-35.el7
abrt-addon-xorg >= 2.1.11-35.el7
abrt-cli >= 2.1.11-35.el7
abrt-console-notification >= 2.1.11-35.el7
abrt-dbus >= 2.1.11-35.el7
abrt-desktop >= 2.1.11-35.el7
abrt-devel >= 2.1.11-35.el7
abrt-gui >= 2.1.11-35.el7
abrt-gui-devel >= 2.1.11-35.el7
abrt-gui-libs >= 2.1.11-35.el7
abrt-libs >= 2.1.11-35.el7
abrt-python >= 2.1.11-35.el7
abrt-python-doc >= 2.1.11-35.el7
abrt-retrace-client >= 2.1.11-35.el7
abrt-tui >= 2.1.11-35.el7
libreport >= 2.1.11-31.el7
libreport-anaconda >= 2.1.11-31.el7
libreport-cli >= 2.1.11-31.el7
libreport-compat >= 2.1.11-31.el7
libreport-devel >= 2.1.11-31.el7
libreport-filesystem >= 2.1.11-31.el7
libreport-gtk >= 2.1.11-31.el7
libreport-gtk-devel >= 2.1.11-31.el7
libreport-newt >= 2.1.11-31.el7
libreport-plugin-bugzilla >= 2.1.11-31.el7
libreport-plugin-kerneloops >= 2.1.11-31.el7
libreport-plugin-logger >= 2.1.11-31.el7
libreport-plugin-mailx >= 2.1.11-31.el7
libreport-plugin-reportuploader >= 2.1.11-31.el7
libreport-python >= 2.1.11-31.el7
libreport-web >= 2.1.11-31.el7
libreport-web-devel >= 2.1.11-31.el7
| Patchnames: RHSA-2015:2505 |
SUSE Timeline for this CVE
CVE page created: Thu Oct 15 19:17:08 2015
CVE page last modified: Mon Oct 30 17:17:42 2023