Medium severity5.5NVD Advisory· Published Jun 26, 2017· Updated May 13, 2026
CVE-2015-1870
CVE-2015-1870
Description
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
Affected products
1- cpe:2.3:a:redhat:automatic_bug_reporting_tool:*:*:*:*:*:*:*:*Range: <=2.1.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/abrt/abrt/commit/7d023c32a565e83306cddf34c894477b7aaf33d1nvdPatchThird Party Advisory
- github.com/abrt/abrt/commit/8939398b82006ba1fec4ed491339fc075f43fc7cnvdPatchThird Party Advisory
- github.com/abrt/libreport/commit/c962918bc70a61a8cc647898ee8b1ff1c14a87c5nvdPatchThird Party Advisory
- rhn.redhat.com/errata/RHSA-2015-1083.htmlnvdVendor Advisory
- www.securityfocus.com/bid/75119nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- rhn.redhat.com/errata/RHSA-2015-1210.htmlnvd
News mentions
0No linked articles in our index yet.