CVE-2012-1106

The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
redhatautomatic_bug_reporting_tool
𝑥
≤ 2.0.7
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
abrt
RHEL 6
0:2.0.8-6.el6
fixed
abrt-addon-ccpp
RHEL 6
0:2.0.8-6.el6
fixed
abrt-addon-kerneloops
RHEL 6
0:2.0.8-6.el6
fixed
abrt-addon-python
RHEL 6
0:2.0.8-6.el6
fixed
abrt-addon-vmcore
RHEL 6
0:2.0.8-6.el6
fixed
abrt-cli
RHEL 6
0:2.0.8-6.el6
fixed
abrt-desktop
RHEL 6
0:2.0.8-6.el6
fixed
abrt-devel
RHEL 6
0:2.0.8-6.el6
fixed
abrt-gui
RHEL 6
0:2.0.8-6.el6
fixed
abrt-libs
RHEL 6
0:2.0.8-6.el6
fixed
abrt-tui
RHEL 6
0:2.0.8-6.el6
fixed
btparser
RHEL 6
0:0.16-3.el6
fixed
btparser-devel
RHEL 6
0:0.16-3.el6
fixed
btparser-python
RHEL 6
0:0.16-3.el6
fixed
libreport
RHEL 6
0:2.0.9-5.el6
fixed
libreport-cli
RHEL 6
0:2.0.9-5.el6
fixed
libreport-devel
RHEL 6
0:2.0.9-5.el6
fixed
libreport-gtk
RHEL 6
0:2.0.9-5.el6
fixed
libreport-gtk-devel
RHEL 6
0:2.0.9-5.el6
fixed
libreport-newt
RHEL 6
0:2.0.9-5.el6
fixed
libreport-plugin-bugzilla
RHEL 6
0:2.0.9-5.el6
fixed
libreport-plugin-kerneloops
RHEL 6
0:2.0.9-5.el6
fixed
libreport-plugin-logger
RHEL 6
0:2.0.9-5.el6
fixed
libreport-plugin-mailx
RHEL 6
0:2.0.9-5.el6
fixed
libreport-plugin-reportuploader
RHEL 6
0:2.0.9-5.el6
fixed
libreport-plugin-rhtsupport
RHEL 6
0:2.0.9-5.el6
fixed
libreport-python
RHEL 6
0:2.0.9-5.el6
fixed
python-meh
RHEL 6
0:0.12.1-3.el6
fixed
Common Weakness Enumeration