CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Abrt Project FedoraprojectRedhat3Abrt Enterprise LinuxFedoraJun 29, 2026 Jun 13, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to...Show more |
3Abrt Project FedoraprojectRedhat3Abrt Enterprise LinuxFedoraJul 15, 2026 Jun 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replace...Show more |
3Abrt Project FedoraprojectRedhat5Abrt Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jan 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABRT might allow attackers to obtain sensitive information from crash reports. |
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment. |