The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Automatic_bug_reporting_tool | Redhat | * | 2.0.7 (including) |
| Red Hat Enterprise Linux 6 | RedHat | abrt-0:2.0.8-6.el6 | * |
| Red Hat Enterprise Linux 6 | RedHat | btparser-0:0.16-3.el6 | * |
| Red Hat Enterprise Linux 6 | RedHat | libreport-0:2.0.9-5.el6 | * |
| Red Hat Enterprise Linux 6 | RedHat | python-meh-0:0.12.1-3.el6 | * |