CVE-2015-5302

CVSS V2 Medium 5 CVSS V3 None
Description
libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report.
Overview
  • CVE ID
  • CVE-2015-5302
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2015-12-07T18:59:03
  • Last Modified Date
  • 2023-02-13T00:53:07
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:redhat:libreport:2.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.0.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.0.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.0.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.0.16:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.0.19:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.0.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.1.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.2.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:redhat:libreport:2.6.2:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:N/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • NONE
  • Availability Impact
  • NONE
  • Base Score
  • 5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 10
  • Impact Score
  • 2.9
History
Created Old Value New Value Data Type Notes
2022-05-10 09:59:16 Added to TrackCVE
2022-12-02 07:22:47 2015-12-07T18:59Z 2015-12-07T18:59:03 CVE Published Date updated
2022-12-02 07:22:47 2016-12-07T18:16:26 CVE Modified Date updated
2022-12-02 07:22:47 Modified Vulnerability Status updated
2023-02-02 17:05:14 2023-02-02T16:17:18 CVE Modified Date updated
2023-02-02 17:05:14 libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report. It was found that ABRT may have exposed non-public information to Red Hat Bugzilla during crash reporting. A bug in the libreport library caused changes made by a user in files included in a crash report to be discarded. As a result, Red Hat Bugzilla attachments may contain data that was not intended to be made public, including host names, IP addresses, or command line options. Description updated
2023-02-02 17:05:20 References updated
2023-02-13 01:06:22 2023-02-13T00:53:07 CVE Modified Date updated
2023-02-13 01:06:22 It was found that ABRT may have exposed non-public information to Red Hat Bugzilla during crash reporting. A bug in the libreport library caused changes made by a user in files included in a crash report to be discarded. As a result, Red Hat Bugzilla attachments may contain data that was not intended to be made public, including host names, IP addresses, or command line options. libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report. Description updated