See how abrt project compares to other vendors in security performance
ABRT might allow attackers to obtain sensitive information from crash reports.
A local privilege escalation flaw was found in abrt, in the way certain core-handlers were specified by the abrt application.
Specifically this issue affects those abrt versions in which the following core-handler was used: HOOKBIN="/usr/sbin/chroot /proc/%P/root @libexecdir@/abrt-hook-ccpp"
This commit was added to abrt via: (To add support for handling crashes inside containers) https://github.com/abrt/abrt/commit/4ab9fbe1a6b7889a0cd59b1406e8789d52171fd2 https://github.com/abrt/abrt/issues/809
But later removed via: https://github.com/abrt/abrt/commit/cdb507ed336fa30151eefa6510d20c9271e7fc82
No version of Red Hat Enterprise Linux or Fedora ships abrt with the above vulnerable code.
Support for containers was re-added in abrt (using a different method this time) via: https://github.com/abrt/abrt/commit/a6cdfd6a16251447264d203e145624a96fa811e3