CVE-2015-5302

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 07 Dec 2015, 18:00
Last modified:06 Aug 2024, 06:41

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
2.82% LOW
3% probability +2.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Dec 2015, 18:00
Published
Vulnerability first disclosed
06 Aug 2024, 06:41
Last Modified
Vulnerability information updated

Description

libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 2.82% Percentile: 86%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • redhatlibreport

    2.0.8 | 2.0.9 | 2.0.10 | 2.0.14 | 2.0.16 | 2.0.19 | 2.0.20 | 2.1.0 | 2.1.1 | 2.1.2 | 2.1.3 | 2.1.4 | 2.1.5 | 2.1.6 | 2.1.7 | 2.1.8 | 2.1.9 | 2.1.10 | 2.1.11 | 2.2.2 | 2.2.3 | 2.3.0 | 2.5.1 | 2.6.2

References (7)