CVE-2015-3151

Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:automatic_bug_reporting_tool:-:*:*:*:*:*:*:*

History

13 Feb 2023, 00:47

Type Values Removed Values Added
Summary Multiple directory traversal flaws were found in the abrt-dbus D-Bus service. A local attacker could use these flaws to read and write arbitrary files as the root user. Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-3151', 'name': 'https://access.redhat.com/security/cve/CVE-2015-3151', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1214451', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1214451', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1083', 'name': 'https://access.redhat.com/errata/RHSA-2015:1083', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 20:20

Type Values Removed Values Added
Summary Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method. Multiple directory traversal flaws were found in the abrt-dbus D-Bus service. A local attacker could use these flaws to read and write arbitrary files as the root user.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-3151 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1214451 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1083 -

Information

Published : 2020-01-14 18:15

Updated : 2023-12-10 13:13


NVD link : CVE-2015-3151

Mitre link : CVE-2015-3151

CVE.ORG link : CVE-2015-3151


JSON object : View

Products Affected

redhat

  • automatic_bug_reporting_tool
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')