CVE-2015-3150

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:automatic_bug_reporting_tool:-:*:*:*:*:*:*:*

History

13 Feb 2023, 00:47

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1083', 'name': 'https://access.redhat.com/errata/RHSA-2015:1083', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-3150', 'name': 'https://access.redhat.com/security/cve/CVE-2015-3150', 'tags': [], 'refsource': 'MISC'}
Summary It was discovered that the abrt-dbus D-Bus service did not properly check the validity of the problem directory argument in the ChownProblemDir, DeleteElement, and DeleteProblem methods. A local attacker could use this flaw take ownership of arbitrary files and directories, or to delete files and directories as the root user. abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

02 Feb 2023, 20:20

Type Values Removed Values Added
Summary abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method. It was discovered that the abrt-dbus D-Bus service did not properly check the validity of the problem directory argument in the ChownProblemDir, DeleteElement, and DeleteProblem methods. A local attacker could use this flaw take ownership of arbitrary files and directories, or to delete files and directories as the root user.
References
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1083 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-3150 -

Information

Published : 2020-01-14 18:15

Updated : 2023-12-10 13:13


NVD link : CVE-2015-3150

Mitre link : CVE-2015-3150

CVE.ORG link : CVE-2015-3150


JSON object : View

Products Affected

redhat

  • automatic_bug_reporting_tool
CWE
CWE-20

Improper Input Validation