CVE-2015-3147: Medium severity red hat automatic bug reporting tool vulnerability
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
Other sources
It was discovered that, when moving problem reports from /var/spool/abrt-upload to /var/spool/abrt or /var/tmp/abrt, abrt-handle-upload does not verify that the new problem directory has appropriate permissions and does not contain symbolic links. A crafted problem report exposes other parts of abrt to attack, and the abrt-handle-upload script allows to overwrite arbitrary files.
Acknowledgement:
This issue was discovered by Florian Weimer of Red Hat Product Security.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3147?
CVE-2015-3147 is classified as a medium severity vulnerability, allowing local users to potentially write to arbitrary files.
How do I fix CVE-2015-3147?
To fix CVE-2015-3147, ensure to update the Automatic Bug Reporting Tool (ABRT) to the latest version provided by Red Hat.
Who is affected by CVE-2015-3147?
CVE-2015-3147 affects users of Red Hat Automatic Bug Reporting Tool on various Red Hat Enterprise Linux versions.
What is the impact of CVE-2015-3147?
The impact of CVE-2015-3147 includes potential unauthorized file writes by local users through a symlink attack.
Is there a workaround for CVE-2015-3147?
A possible workaround for CVE-2015-3147 is to restrict user access to the directories involved in the bug reporting process.