First published: Wed Apr 22 2015(Updated: )
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Automatic Bug Reporting Tool |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3150 has a moderate severity level due to its impact on local users' ability to modify system files.
To mitigate CVE-2015-3150, update the Automatic Bug Reporting Tool (ABRT) to the latest version provided by Red Hat.
CVE-2015-3150 affects local users of the Red Hat Automatic Bug Reporting Tool.
The vulnerable methods in CVE-2015-3150 include ChownProblemDir, DeleteElement, and DeleteProblem.
A workaround for CVE-2015-3150 is to restrict access to the ABRT D-Bus services to trusted users only.