CVE-2012-5659
12.03.2013, 23:55
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | automatic_bug_reporting_tool | 𝑥 ≤ 2.0.9 |
| redhat | automatic_bug_reporting_tool | 2.0.0 |
| redhat | automatic_bug_reporting_tool | 2.0.1 |
| redhat | automatic_bug_reporting_tool | 2.0.2 |
| redhat | automatic_bug_reporting_tool | 2.0.3 |
| redhat | automatic_bug_reporting_tool | 2.0.4 |
| redhat | automatic_bug_reporting_tool | 2.0.4.980 |
| redhat | automatic_bug_reporting_tool | 2.0.4.981 |
| redhat | automatic_bug_reporting_tool | 2.0.5 |
| redhat | automatic_bug_reporting_tool | 2.0.6 |
| redhat | automatic_bug_reporting_tool | 2.0.7 |
| redhat | automatic_bug_reporting_tool | 2.0.8 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| abrt |
| ||
| abrt-addon-ccpp |
| ||
| abrt-addon-kerneloops |
| ||
| abrt-addon-python |
| ||
| abrt-addon-vmcore |
| ||
| abrt-cli |
| ||
| abrt-desktop |
| ||
| abrt-devel |
| ||
| abrt-gui |
| ||
| abrt-libs |
| ||
| abrt-tui |
| ||
| libreport |
| ||
| libreport-cli |
| ||
| libreport-devel |
| ||
| libreport-gtk |
| ||
| libreport-gtk-devel |
| ||
| libreport-newt |
| ||
| libreport-plugin-bugzilla |
| ||
| libreport-plugin-kerneloops |
| ||
| libreport-plugin-logger |
| ||
| libreport-plugin-mailx |
| ||
| libreport-plugin-reportuploader |
| ||
| libreport-plugin-rhtsupport |
| ||
| libreport-python |
|
References