Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-3142
Description:The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-3142
75116
http://www.securityfocus.com/bid/75116
RHSA-2015:1083
http://rhn.redhat.com/errata/RHSA-2015-1083.html
RHSA-2015:1210
http://rhn.redhat.com/errata/RHSA-2015-1210.html
[oss-security] 20150417 Re: Problems in automatic crash analysis frameworks
http://www.openwall.com/lists/oss-security/2015/04/17/5
https://bugzilla.redhat.com/show_bug.cgi?id=1212818
https://bugzilla.redhat.com/show_bug.cgi?id=1212818




© 1998-2025 E-Soft Inc. All rights reserved.