ELSA-2015-1083

ELSA-2015-1083 - abrt security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2015-06-09

Description


abrt
[2.1.11-22.0.1]
- Drop libreport-rhel and libreport-plugin-rhtsupport requires

[2.1.11-22]
- do not open the build_ids file as the user abrt
- do not unlink failed and big user core files
- Related: #1212819, #1216973

[2.1.11-21]
- validate all D-Bus method arguments
- Related: #1214610

[2.1.11-20]
- remove the old dump directories during upgrade
- abrt-action-install-debuginfo-to-abrt-cache: sanitize arguments and umask
- fix race conditions and directory traversal issues in abrt-dbus
- use /var/spool/abrt instead of /var/tmp/abrt
- make the problem directories owned by root and the group abrt
- validate uploaded problem directories in abrt-handle-upload
- don't override files with user core dump files
- fix symbolic link and race condition flaws
- Resolves: #1211969, #1212819, #1212863, #1212869
- Resolves: #1214453, #1214610, #1216973, #1218583

libreport
[2.1.11-23.0.1]
- Update workflow xml for Oracle [18945470]
- Add oracle-enterprise.patch and oracle-enterprise-po.patch
- Remove libreport-plugin-rhtsupport and libreport-rhel
- Added orabug20390725.patch to remove redhat reference [bug 20390725]
- Added Bug20357383.patch to remove redhat reference [bug 20357383]

[2.1.11-23]
- do not open files outside a dump directory
- Related: #1217484

[2.1.11-22]
- switch the default dump dir mode to 0750
- harden against directory traversal, crafted symbolic links
- avoid race-conditions in dump dir opening
- Resolves: #1212096, #1217499, #1218610, #1217484


Related CVEs


CVE-2015-1869
CVE-2015-1870
CVE-2015-3142
CVE-2015-3147
CVE-2015-3150
CVE-2015-3151
CVE-2015-3159
CVE-2015-3315

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) abrt-2.1.11-22.0.1.el7_1.src.rpmaf6105b4efb7dbacd302af1126719efaELBA-2020-3912
libreport-2.1.11-23.0.1.el7_1.src.rpm6ade8c23a024f273f5053bbaaacd2abeELBA-2020-1040
abrt-2.1.11-22.0.1.el7_1.x86_64.rpmf11928f3a77903e98f6b8e87d64d2548ELBA-2020-3912
abrt-addon-ccpp-2.1.11-22.0.1.el7_1.x86_64.rpmfbfd79932e3a162468da694830c6d85aELBA-2020-3912
abrt-addon-kerneloops-2.1.11-22.0.1.el7_1.x86_64.rpm46fac57a3718d6aa9dec8ead9974f08dELBA-2020-3912
abrt-addon-pstoreoops-2.1.11-22.0.1.el7_1.x86_64.rpm59735453d9fe8f72fad075cbfe1ac3a9ELBA-2020-3912
abrt-addon-python-2.1.11-22.0.1.el7_1.x86_64.rpm896b4ac98f9ffd5859b9d8f266735029ELBA-2020-3912
abrt-addon-upload-watch-2.1.11-22.0.1.el7_1.x86_64.rpmb1ecaf1678a0d282050320943a6a840fELBA-2020-3912
abrt-addon-vmcore-2.1.11-22.0.1.el7_1.x86_64.rpm8188a0815e66cf38b165d679f9501553ELBA-2020-3912
abrt-addon-xorg-2.1.11-22.0.1.el7_1.x86_64.rpmbc17120f7c2564633840cb805de3d4e5ELBA-2020-3912
abrt-cli-2.1.11-22.0.1.el7_1.x86_64.rpmdf6c82e9baaa5c6b17d09b8ca0f004d2ELBA-2020-3912
abrt-console-notification-2.1.11-22.0.1.el7_1.x86_64.rpm7f0b933a5caa52d4268729c76e8acf8aELBA-2020-3912
abrt-dbus-2.1.11-22.0.1.el7_1.x86_64.rpmaccb12eb7e8e851a1a341cdf492499fcELBA-2020-3912
abrt-desktop-2.1.11-22.0.1.el7_1.x86_64.rpmfaa71e8dff1da39c4fd43ce0d80544adELBA-2020-3912
abrt-devel-2.1.11-22.0.1.el7_1.i686.rpm30fe1f4049c9e32a1c46abb20bf7a7c5ELBA-2020-3912
abrt-devel-2.1.11-22.0.1.el7_1.x86_64.rpm78992e9717e91ccebf6afbe4558a7679ELBA-2020-3912
abrt-gui-2.1.11-22.0.1.el7_1.x86_64.rpmfa30a30b0c1c5442462a86dc5dade5fbELBA-2020-3912
abrt-gui-devel-2.1.11-22.0.1.el7_1.i686.rpm6736536be6a2963e34dcccdf788d61ffELBA-2020-3912
abrt-gui-devel-2.1.11-22.0.1.el7_1.x86_64.rpmf6632ad955293aa2d97a5c2266bd31b9ELBA-2020-3912
abrt-gui-libs-2.1.11-22.0.1.el7_1.i686.rpma5d4a64dc2a0265d5eaf502f650e3fe9ELBA-2020-3912
abrt-gui-libs-2.1.11-22.0.1.el7_1.x86_64.rpmdf26334294bcf74b632c82594fa3d779ELBA-2020-3912
abrt-libs-2.1.11-22.0.1.el7_1.i686.rpm70e27ed2b4062e49ac3d8f4dc0dbb1b6ELBA-2020-3912
abrt-libs-2.1.11-22.0.1.el7_1.x86_64.rpm0a2f0ab2d50dbef0baf8075dca555148ELBA-2020-3912
abrt-python-2.1.11-22.0.1.el7_1.x86_64.rpm259047cbef104d91447dcc9878ad299cELBA-2020-3912
abrt-python-doc-2.1.11-22.0.1.el7_1.noarch.rpmfcc4a85a7beba2b3a7067b847b195cfeELBA-2020-3912
abrt-retrace-client-2.1.11-22.0.1.el7_1.x86_64.rpmdf65de512141dda11e9001399e172711ELBA-2020-3912
abrt-tui-2.1.11-22.0.1.el7_1.x86_64.rpm0876073b7ba5573af012791419b865b6ELBA-2020-3912
libreport-2.1.11-23.0.1.el7_1.i686.rpm3e63b89a50c742319d6a8a46869907bdELBA-2020-1040
libreport-2.1.11-23.0.1.el7_1.x86_64.rpm5c0c52ac16647f30d1791d03127a7164ELBA-2020-1040
libreport-anaconda-2.1.11-23.0.1.el7_1.x86_64.rpma4b8a5c58197310802c62e5242f9a0f8ELBA-2020-1040
libreport-cli-2.1.11-23.0.1.el7_1.x86_64.rpm7e477729359486d6466bb6c6a8a391a9ELBA-2020-1040
libreport-compat-2.1.11-23.0.1.el7_1.x86_64.rpmc2df16f4c58439992747ea4bd90d8729ELBA-2020-1040
libreport-devel-2.1.11-23.0.1.el7_1.i686.rpm54a9551717ff219f4f8cfc92a402c6a6ELBA-2020-1040
libreport-devel-2.1.11-23.0.1.el7_1.x86_64.rpmd3e35b8caf6803871f8775dd00fd15aaELBA-2020-1040
libreport-filesystem-2.1.11-23.0.1.el7_1.x86_64.rpm241eecec94de8e843b5502e378b34e84ELBA-2020-1040
libreport-gtk-2.1.11-23.0.1.el7_1.i686.rpm93380d9c1d455346f9afc800fd41fd17ELBA-2020-1040
libreport-gtk-2.1.11-23.0.1.el7_1.x86_64.rpmeac14503220d60eae54f77d5a73ff123ELBA-2020-1040
libreport-gtk-devel-2.1.11-23.0.1.el7_1.i686.rpm0320e1a120452489ecce98678b4edb28ELBA-2020-1040
libreport-gtk-devel-2.1.11-23.0.1.el7_1.x86_64.rpm4af81639e7fa977c8c18c3c5087f6d3fELBA-2020-1040
libreport-newt-2.1.11-23.0.1.el7_1.x86_64.rpm8608c4dc7181fb7e6baa6cf7b0e61fb6ELBA-2020-1040
libreport-plugin-bugzilla-2.1.11-23.0.1.el7_1.x86_64.rpm5c40b7f4dce35289f62928c1a203ac3dELBA-2020-1040
libreport-plugin-kerneloops-2.1.11-23.0.1.el7_1.x86_64.rpmc88d03177a7147847ddeb27f4c2be35cELBA-2020-1040
libreport-plugin-logger-2.1.11-23.0.1.el7_1.x86_64.rpmab1a40d0394920324e62f5ea48fd6b58ELBA-2020-1040
libreport-plugin-mailx-2.1.11-23.0.1.el7_1.x86_64.rpm524819dc98d39df3d8975c334972d270ELBA-2020-1040
libreport-plugin-reportuploader-2.1.11-23.0.1.el7_1.x86_64.rpm201e888fa145482456bf40215cc785c7ELBA-2020-1040
libreport-plugin-ureport-2.1.11-23.0.1.el7_1.x86_64.rpm594e7d58e6e39746e3ebe169f4d3ac05ELBA-2020-1040
libreport-python-2.1.11-23.0.1.el7_1.x86_64.rpm23351020a41c407512916c95902a7d97ELBA-2020-1040
libreport-rhel-anaconda-bugzilla-2.1.11-23.0.1.el7_1.x86_64.rpm03e4ecf41baf84eb3d5bca8a452a020dELBA-2020-1040
libreport-rhel-bugzilla-2.1.11-23.0.1.el7_1.x86_64.rpm247a7d5e6cee8aa30f16a8f46e099aebELBA-2020-1040
libreport-web-2.1.11-23.0.1.el7_1.i686.rpm3ac71ee14b55a7d48afd5807a1769a99ELBA-2020-1040
libreport-web-2.1.11-23.0.1.el7_1.x86_64.rpm021812de7eeded617281d01a65864a52ELBA-2020-1040
libreport-web-devel-2.1.11-23.0.1.el7_1.i686.rpm737d325132cf1abd9315c27092caea7bELBA-2020-1040
libreport-web-devel-2.1.11-23.0.1.el7_1.x86_64.rpm59641ed52934f069ab9ab2de18bcc448ELBA-2020-1040



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete