Vulnerability Description
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Automatic Bug Reporting Tool | - |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-3151Issue TrackingThird Party Advisory
- https://github.com/abrt/abrt/commit/7a47f57975be0d285a2f20758e4572dca6d9cdd3PatchThird Party Advisory
- https://github.com/abrt/abrt/commit/c796c76341ee846cfb897ed645bac211d7d0a932PatchThird Party Advisory
- https://github.com/abrt/abrt/commit/f3c2a6af3455b2882e28570e8a04f1c2d4500d5bPatchThird Party Advisory
- https://github.com/abrt/libreport/commit/239c4f7d1f47265526b39ad70106767d0080527PatchThird Party Advisory
- https://github.com/abrt/libreport/commit/54ecf8d017580b495d6501e53ca54e453a73a36PatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-3151Issue TrackingThird Party Advisory
- https://github.com/abrt/abrt/commit/7a47f57975be0d285a2f20758e4572dca6d9cdd3PatchThird Party Advisory
- https://github.com/abrt/abrt/commit/c796c76341ee846cfb897ed645bac211d7d0a932PatchThird Party Advisory
- https://github.com/abrt/abrt/commit/f3c2a6af3455b2882e28570e8a04f1c2d4500d5bPatchThird Party Advisory
- https://github.com/abrt/libreport/commit/239c4f7d1f47265526b39ad70106767d0080527PatchThird Party Advisory
- https://github.com/abrt/libreport/commit/54ecf8d017580b495d6501e53ca54e453a73a36PatchThird Party Advisory
FAQ
What is CVE-2015-3151?
CVE-2015-3151 is a vulnerability with a CVSS score of 7.8 (HIGH). Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) Ne...
How severe is CVE-2015-3151?
CVE-2015-3151 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3151?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Automatic Bug Reporting Tool.