The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Automatic_bug_reporting_tool | Redhat | * | 2.0.7 (including) |
Red Hat Enterprise Linux 6 | RedHat | abrt-0:2.0.8-6.el6 | * |
Red Hat Enterprise Linux 6 | RedHat | btparser-0:0.16-3.el6 | * |
Red Hat Enterprise Linux 6 | RedHat | libreport-0:2.0.9-5.el6 | * |
Red Hat Enterprise Linux 6 | RedHat | python-meh-0:0.12.1-3.el6 | * |