Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 461846 (CVE-2012-5659) - <app-admin/abrt-2.0.9: two vulnerabilities (CVE-2012-{5659,5660})
Summary: <app-admin/abrt-2.0.9: two vulnerabilities (CVE-2012-{5659,5660})
Status: RESOLVED FIXED
Alias: CVE-2012-5659
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-15 19:26 UTC by Agostino Sarubbo
Modified: 2013-09-18 05:04 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-03-15 19:26:10 UTC
From ${URL} :

Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in 
Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute 
arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious 
Python module.
Comment 1 Agostino Sarubbo gentoo-dev 2013-03-17 14:07:35 UTC
and http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5660 :

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-03-19 20:17:07 UTC
CVE-2012-5660 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5660):
  abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9
  and earlier allows local users to set world-writable permissions for
  arbitrary files and possibly gain privileges via a symlink attack on "the
  directories used to store information about crashes."

CVE-2012-5659 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5659):
  Untrusted search path vulnerability in
  plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug
  Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and
  execute arbitrary Python modules by modifying the PYTHONPATH environment
  variable to reference a malicious Python module.
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-17 00:11:53 UTC
2.0.13 is in tree and stable. GLSA vote: no.
Comment 4 Sergey Popov (RETIRED) gentoo-dev 2013-09-18 05:04:29 UTC
GLSA vote: no

Closing as noglsa