VYPR

Libreport

by Red Hat

Source repositories

CVEs (3)

  • CVE-2026-54230HigJun 13, 2026
    risk 0.45cvss 7.0epss

    A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows…

  • CVE-2026-54231MedJun 13, 2026
    risk 0.36cvss 5.5epss

    A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded…

  • CVE-2015-5302Dec 7, 2015
    risk 0.00cvss epss 0.01

    libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7)…