CVE-2015-5302

libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
redhatlibreport
2.0.8
redhatlibreport
2.0.9
redhatlibreport
2.0.10
redhatlibreport
2.0.14
redhatlibreport
2.0.16
redhatlibreport
2.0.19
redhatlibreport
2.0.20
redhatlibreport
2.1.0
redhatlibreport
2.1.1
redhatlibreport
2.1.2
redhatlibreport
2.1.3
redhatlibreport
2.1.4
redhatlibreport
2.1.5
redhatlibreport
2.1.6
redhatlibreport
2.1.7
redhatlibreport
2.1.8
redhatlibreport
2.1.9
redhatlibreport
2.1.10
redhatlibreport
2.1.11
redhatlibreport
2.2.2
redhatlibreport
2.2.3
redhatlibreport
2.3.0
redhatlibreport
2.5.1
redhatlibreport
2.6.2
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
abrt
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-ccpp
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-kerneloops
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-pstoreoops
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-python
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-upload-watch
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-vmcore
RHEL 7
0:2.1.11-35.el7
fixed
abrt-addon-xorg
RHEL 7
0:2.1.11-35.el7
fixed
abrt-cli
RHEL 7
0:2.1.11-35.el7
fixed
abrt-console-notification
RHEL 7
0:2.1.11-35.el7
fixed
abrt-dbus
RHEL 7
0:2.1.11-35.el7
fixed
abrt-desktop
RHEL 7
0:2.1.11-35.el7
fixed
abrt-devel
RHEL 7
0:2.1.11-35.el7
fixed
abrt-gui
RHEL 7
0:2.1.11-35.el7
fixed
abrt-gui-devel
RHEL 7
0:2.1.11-35.el7
fixed
abrt-gui-libs
RHEL 7
0:2.1.11-35.el7
fixed
abrt-libs
RHEL 7
0:2.1.11-35.el7
fixed
abrt-python
RHEL 7
0:2.1.11-35.el7
fixed
abrt-python-doc
RHEL 7
0:2.1.11-35.el7
fixed
abrt-retrace-client
RHEL 7
0:2.1.11-35.el7
fixed
abrt-tui
RHEL 7
0:2.1.11-35.el7
fixed
libreport
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-anaconda
RHEL 7
0:2.1.11-31.el7
fixed
libreport-cli
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-compat
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-devel
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-filesystem
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-gtk
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-gtk-devel
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-newt
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-bugzilla
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-kerneloops
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-logger
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-mailx
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-reportuploader
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-rhtsupport
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-plugin-ureport
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-python
RHEL 6
0:2.0.9-25.el6_7
fixed
RHEL 7
0:2.1.11-31.el7
fixed
libreport-rhel
RHEL 7
0:2.1.11-31.el7
fixed
libreport-rhel-anaconda-bugzilla
RHEL 7
0:2.1.11-31.el7
fixed
libreport-rhel-bugzilla
RHEL 7
0:2.1.11-31.el7
fixed
libreport-web
RHEL 7
0:2.1.11-31.el7
fixed
libreport-web-devel
RHEL 7
0:2.1.11-31.el7
fixed