abrt-2.0.8-26.1.0.1.AXS4, libreport-2.0.9-21.1.0.1.AXS4
エラータID: AXSA:2015-183:01
リリース日:
2015/07/10 Friday - 19:12
題名:
abrt-2.0.8-26.1.0.1.AXS4, libreport-2.0.9-21.1.0.1.AXS4
影響のあるチャネル:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- 現時点では CVE-2015-1869, CVE-2015-1870, CVE-2015-3142, CVE-2015-3147, CVE-2015-3159, CVE-2015-3315 の情報が公開されておりません。
CVE の情報が公開され次第情報をアップデートいたします。
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2015-1869
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2015-1870
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
CVE-2015-3142
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
CVE-2015-3147
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2015-3159
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to librpm.
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to librpm.
追加情報:
N/A
ダウンロード:
SRPMS
- abrt-2.0.8-26.1.0.1.AXS4.src.rpm
MD5: cc01798098749260c8de169acd433d3b
SHA-256: c97893bab2b6f4a6567e637c0e7eb2e53dbf19c4e27caf9511fe9e7b3bec2cda
Size: 1.77 MB - libreport-2.0.9-21.1.0.1.AXS4.src.rpm
MD5: 051df31811534d98a1189d3948a8dc07
SHA-256: fc39985f599315f3beef9688e1b62ea46fe9b77139599a0e72f40b98a2b14967
Size: 1.95 MB
Asianux Server 4 for x86
- abrt-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 3718e6a8d648fdded8c696587748ee53
SHA-256: aabc5c294285cd7a47b03ab30e59d710c49bb1b25ea34079440fcb0d8ff5463a
Size: 212.66 kB - abrt-addon-ccpp-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 5b97b466b17cb187d5791e7add586e08
SHA-256: c1fc88dd65e1c3a2c8ca9c989e4e7225cf51ad399aa3c5a0abe88f9dafe0b815
Size: 117.41 kB - abrt-addon-kerneloops-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 8dd09de6c9cef0cac6daa868a3fa1866
SHA-256: 76e930911ce090f01614c275b184551d271c16329c02ed3f8546abc2d6e69e78
Size: 67.43 kB - abrt-addon-python-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: e6d0f010e58f852a880e14437bd8d345
SHA-256: c3dbbb88d5e1f3319e157069527f57d72f4e00f9eb7661287e91d41de9e5c17c
Size: 65.42 kB - abrt-cli-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 8188e5b0cfd89aa6a0f77e9bc875116d
SHA-256: 6b4395c93293a9578a44d6ee6b9f4bb276fec79a507cfa628323d4a64f0c554e
Size: 54.90 kB - abrt-desktop-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 524d8e0071920628186ada6efa932c39
SHA-256: 2881e700db120ee5c3fc8a3d5624a96ee08c1df82fd3f74cda6a994c75bb4f05
Size: 55.02 kB - abrt-gui-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 11a0fa719bf7afaa6f2ecdb882984578
SHA-256: 0c0f333cefc5e33d24f1145c581cd53d7a1df09ffe1db2a81125a926a64aa160
Size: 152.82 kB - abrt-libs-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: f444c869bfbf285ddd93b6b71ec6c0c3
SHA-256: 43c05b5be4c73ca9fd3c4de7b7483516e01c151e06891a60df32266fa2021fb1
Size: 65.99 kB - abrt-tui-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: 6165abac9ec99cdb0405ad8dfb6a0482
SHA-256: 3b9c55c1a27a9c5855e5a3d69e2b882df8e00a2f7a62543a79ae8a7b87ca6072
Size: 62.70 kB - libreport-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: f1977d0d07e72c38df7b524beaf16ac4
SHA-256: 93fdd4216c34f5689337c9ae057bc0450354106170b5356ee2e17b18eb705f02
Size: 247.00 kB - libreport-cli-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 420295df19aa6e54197766ddbe8dba38
SHA-256: 08c72f702c4dfbc0f6439acb91a9018917fdcdf00261e8a73e80eba54eca1895
Size: 23.02 kB - libreport-compat-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 63a6c67fdd4e25d72d7f94d8568f3bb7
SHA-256: 24c50257eed29ce41aef01982f25bde02d5467643b66122880cf31ce74c24c80
Size: 15.56 kB - libreport-gtk-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 7df32de4aafae8c619c30b1f7c19851c
SHA-256: 596b4e61089dc4dce8d579b981c8ba1dfee2ded29fd2ee6ac9810eb820fdf9e0
Size: 43.63 kB - libreport-newt-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 4dea126b9bc22d3df2803be77f6f7e5a
SHA-256: 996643bb4695549f08f20132df62f425710342e66ca46a9a18bd12cfb301f402
Size: 17.66 kB - libreport-plugin-kerneloops-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 6fd251e74ea5034fcd2d862ce45bd62b
SHA-256: baa9157e092f9dd0ace7e558e815d0fd27b5517f7d04ec1c6e252b8937b7aa52
Size: 19.08 kB - libreport-plugin-logger-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: acfbc72691c06f01cc8f64711843a0f0
SHA-256: 08af9b1b9420d16c839ffc1c1847eb3e8a2c81c6214283838dfceca957149800
Size: 20.84 kB - libreport-plugin-mailx-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: dab0faffcc41c5c76b4cb0a980f8bf7d
SHA-256: fc1b32e89bc7d3b924748a5e6fada7b575de137e809e669ead083b306fb10a75
Size: 22.21 kB - libreport-plugin-reportuploader-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 08055cbe329db15f88d09aa28eec791b
SHA-256: 5a5a64d79fe2dde87b1cd45460e918adeb115ce9ae84e162088719861f337ff9
Size: 23.68 kB - libreport-plugin-rhtsupport-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 02d0af479ac459b9a71d78b5334fa788
SHA-256: 3dbf990f22cdc354a43893f28411a68600400cb5fdc93cd0a38ea9e4273dc592
Size: 29.06 kB - libreport-python-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: b26741222b9119152956947804ba4bcf
SHA-256: 9c1f4158ba355d88e1cbf205484ec254e8aa3b1fa0c7999eb68c0a03023c658c
Size: 34.90 kB
Asianux Server 4 for x86_64
- abrt-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: 7016674fad063fd2562a4d539d04e813
SHA-256: e07207cceedd818a8768130898c49cbf0b5500bdc38c1879821c9ed8b551c667
Size: 211.74 kB - abrt-addon-ccpp-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: e46297eb3c3c97c3d3f954e00246abcf
SHA-256: 740650a00365922882bd37471ee07f9d501ea07c98f04ccb6e7256f819801564
Size: 117.46 kB - abrt-addon-kerneloops-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: f9c2f2c6588f575d11e5dc93f41f15bc
SHA-256: 3c357adf857a89b36e11a5d6048d75f7c78b5d2c0c7b182b5c86a2ad402aa35b
Size: 66.98 kB - abrt-addon-python-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: dcb37e845aea360f69bb3fcf79e5596f
SHA-256: 6c2be606a14ae4f093ccdcdb4e304658d5faad43a48aeca4cdf415f03a732572
Size: 65.04 kB - abrt-cli-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: b2d4802e6853fb3eaf632986ca17d721
SHA-256: 37eab0aff9ec3d1c5815b3fedb25764a59fb5c7d1775ad50e8d0a7b90bf488a8
Size: 54.45 kB - abrt-desktop-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: 443876e4912daf18d283d1ef72ad766a
SHA-256: 1a1365c670d63694b1a905ed97cc5f22a6c7c4ff4606b12ad91ca49bc69d26fd
Size: 54.58 kB - abrt-gui-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: 1ac7e25ddecad1462c5a55d9dd76bf11
SHA-256: 13e5976db1ad9aa5d09892dab5726dad1e4eef2c9f4d278de4153ce2539f692b
Size: 152.32 kB - abrt-libs-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: 3678e5a3fb6cbe03623a70ca55416f60
SHA-256: d8ce392658fc7d2b75069e2793919acb6614a4c1e39f4b51a2ffae6e374ed719
Size: 65.43 kB - abrt-tui-2.0.8-26.1.0.1.AXS4.x86_64.rpm
MD5: 8f87e9d50d602c84db8e58ae9323bc10
SHA-256: 0fdc5fcc9999923888e6fcd3dec0d938007ff17c0096a5b664ad41573eff24c5
Size: 62.38 kB - abrt-libs-2.0.8-26.1.0.1.AXS4.i686.rpm
MD5: f444c869bfbf285ddd93b6b71ec6c0c3
SHA-256: 43c05b5be4c73ca9fd3c4de7b7483516e01c151e06891a60df32266fa2021fb1
Size: 65.99 kB - libreport-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: ec01ca773922f1712e4bc9aee3a8f76e
SHA-256: b9706d1cbe802526205dd657275a30c3c121f464184c1e819d81f9cdb2f03bd3
Size: 246.17 kB - libreport-cli-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 1e8eda71085772a28adb46b443c4c8f5
SHA-256: cdc901c5e25abe9e66dd7d4c146ed4fe7bf0483d6facdf9d0b23719dafde9a77
Size: 22.72 kB - libreport-compat-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 3faff862eae8386efa49813790d3a526
SHA-256: ae8f0e6872eff8a5298cd9a72794b00d644ecb5c7d91d0967d30d7c7a77ccdec
Size: 15.19 kB - libreport-gtk-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 8e02e7e48b027440b6fcb7710583a72e
SHA-256: 7679872e06d0ebe5795b6a57b03839d90277e69d2202b294ad2b7bae3714d70b
Size: 43.79 kB - libreport-newt-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 1a948e52768b063af593e4d01eca3e26
SHA-256: f2452b8dc346789dae1cf2576c0dce380eac4578d0da55209ef4bce8fa61d159
Size: 17.45 kB - libreport-plugin-kerneloops-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 4a16904daa4ab3f327ef79e801c43279
SHA-256: 61d8e572b393e014fb1a08a8aa9e498ac13a5c7ffc3cb85a9d498b35c26022ee
Size: 18.83 kB - libreport-plugin-logger-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 63e414ac7877dad52880087b1da848ab
SHA-256: 672ccc31a1ca51f8e0f6630ed630cbeebacb10347d798b63c1d5b10a65a1b914
Size: 20.52 kB - libreport-plugin-mailx-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: a0b456dfb2aea4bf9902187fa2461e92
SHA-256: 148035b8b21df292324cee8ef15d60167efaa75dd56a52c3da6e7cd672170adf
Size: 21.91 kB - libreport-plugin-reportuploader-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: 798a9b1c0726b0532a88ddda16a94e79
SHA-256: f7aa36e1ed1dba63a9f197453076942e0dbc0661b66b2fdc1a538c405cd33096
Size: 23.45 kB - libreport-plugin-rhtsupport-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: cc09e2a2e39c0f7448ac08ffab76ef47
SHA-256: ea3df073cedf2e5f0a7f01d2e77dfcbec8910534cfd71f29e54d5f3755fef394
Size: 28.81 kB - libreport-python-2.0.9-21.1.0.1.AXS4.x86_64.rpm
MD5: fd62ad423ad8089605435c844f1377d5
SHA-256: 6a02857086af81b5c2929ed9290ff9f3ee7c857098982b939cdee28842c06542
Size: 34.64 kB - libreport-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: f1977d0d07e72c38df7b524beaf16ac4
SHA-256: 93fdd4216c34f5689337c9ae057bc0450354106170b5356ee2e17b18eb705f02
Size: 247.00 kB - libreport-gtk-2.0.9-21.1.0.1.AXS4.i686.rpm
MD5: 7df32de4aafae8c619c30b1f7c19851c
SHA-256: 596b4e61089dc4dce8d579b981c8ba1dfee2ded29fd2ee6ac9810eb820fdf9e0
Size: 43.63 kB