Scientific Linux Security Update : abrt and libreport on SL6.x i386/x86_64 (20130131)

medium Nessus Plugin ID 64423

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

It was found that the /usr/libexec/abrt-action-install-debuginfo-to-abrt-cache tool did not sufficiently sanitize its environment variables. This could lead to Python modules being loaded and run from non-standard directories (such as /tmp/). A local attacker could use this flaw to escalate their privileges to that of the abrt user. (CVE-2012-5659)

A race condition was found in the way ABRT handled the directories used to store information about crashes. A local attacker with the privileges of the abrt user could use this flaw to perform a symbolic link attack, possibly allowing them to escalate their privileges to root. (CVE-2012-5660)

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?18500da3

Plugin Details

Severity: Medium

ID: 64423

File Name: sl_20130131_abrt_and_libreport_on_SL6_x.nasl

Version: 1.7

Type: local

Agent: unix

Published: 2/4/2013

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:abrt, p-cpe:/a:fermilab:scientific_linux:abrt-addon-ccpp, p-cpe:/a:fermilab:scientific_linux:abrt-addon-kerneloops, p-cpe:/a:fermilab:scientific_linux:abrt-addon-python, p-cpe:/a:fermilab:scientific_linux:abrt-addon-vmcore, p-cpe:/a:fermilab:scientific_linux:abrt-cli, p-cpe:/a:fermilab:scientific_linux:abrt-debuginfo, p-cpe:/a:fermilab:scientific_linux:abrt-desktop, p-cpe:/a:fermilab:scientific_linux:abrt-devel, p-cpe:/a:fermilab:scientific_linux:abrt-gui, p-cpe:/a:fermilab:scientific_linux:abrt-libs, p-cpe:/a:fermilab:scientific_linux:abrt-tui, p-cpe:/a:fermilab:scientific_linux:libreport, p-cpe:/a:fermilab:scientific_linux:libreport-cli, p-cpe:/a:fermilab:scientific_linux:libreport-debuginfo, p-cpe:/a:fermilab:scientific_linux:libreport-devel, p-cpe:/a:fermilab:scientific_linux:libreport-gtk, p-cpe:/a:fermilab:scientific_linux:libreport-gtk-devel, p-cpe:/a:fermilab:scientific_linux:libreport-newt, p-cpe:/a:fermilab:scientific_linux:libreport-plugin-bugzilla, p-cpe:/a:fermilab:scientific_linux:libreport-plugin-kerneloops, p-cpe:/a:fermilab:scientific_linux:libreport-plugin-logger, p-cpe:/a:fermilab:scientific_linux:libreport-plugin-mailx, p-cpe:/a:fermilab:scientific_linux:libreport-plugin-reportuploader, p-cpe:/a:fermilab:scientific_linux:libreport-plugin-rhtsupport, p-cpe:/a:fermilab:scientific_linux:libreport-python, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 1/31/2013

Vulnerability Publication Date: 3/12/2013

Reference Information

CVE: CVE-2012-5659, CVE-2012-5660