RHEL 6 : abrt, libreport, btparser, and python-meh (RHSA-2012:0841)

high Nessus Plugin ID 59589

Synopsis

The remote Red Hat host is missing one or more security updates for abrt / libreport / btparser / python-meh.

Description

The remote Redhat Enterprise Linux 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2012:0841 advisory.

ABRT (Automatic Bug Reporting Tool) is a tool to help users to detect defects in applications and to create a bug report with all the information needed by a maintainer to fix it. It uses a plug-in system to extend its functionality. libreport provides an API for reporting different problems in applications to different bug targets, such as Bugzilla, FTP, and Trac.

The btparser utility is a backtrace parser and analyzer library, which works with backtraces produced by the GNU Project Debugger. It can parse a text file with a backtrace to a tree of C structures, allowing to analyze the threads and frames of the backtrace and process them.

The python-meh package provides a python library for handling exceptions.

If the C handler plug-in in ABRT was enabled (the abrt-addon-ccpp package installed and the abrt-ccpp service running), and the sysctl fs.suid_dumpable option was set to 2 (it is 0 by default), core dumps of set user ID (setuid) programs were created with insecure group ID permissions. This could allow local, unprivileged users to obtain sensitive information from the core dump files of setuid processes they would otherwise not be able to access. (CVE-2012-1106)

ABRT did not allow users to easily search the collected crash information for sensitive data prior to submitting it. This could lead to users unintentionally exposing sensitive information via the submitted crash reports. This update adds functionality to search across all the collected data. Note that this fix does not apply to the default configuration, where reports are sent to Red Hat Customer Support. It only takes effect for users sending information to Red Hat Bugzilla. (CVE-2011-4088)

Red Hat would like to thank Jan Iven for reporting CVE-2011-4088.

These updated packages include numerous bug fixes. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.3 Technical Notes for information on the most significant of these changes.

All users of abrt, libreport, btparser, and python-meh are advised to upgrade to these updated packages, which correct these issues.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL abrt / libreport / btparser / python-meh packages based on the guidance in RHSA-2012:0841.

See Also

http://www.nessus.org/u?82c00edc

http://www.nessus.org/u?99c170a7

https://access.redhat.com/errata/RHSA-2012:0841

https://access.redhat.com/security/updates/classification/#low

https://bugzilla.redhat.com/show_bug.cgi?id=625485

https://bugzilla.redhat.com/show_bug.cgi?id=727494

https://bugzilla.redhat.com/show_bug.cgi?id=745976

https://bugzilla.redhat.com/show_bug.cgi?id=746727

https://bugzilla.redhat.com/show_bug.cgi?id=747594

https://bugzilla.redhat.com/show_bug.cgi?id=747624

https://bugzilla.redhat.com/show_bug.cgi?id=749100

https://bugzilla.redhat.com/show_bug.cgi?id=749854

https://bugzilla.redhat.com/show_bug.cgi?id=751068

https://bugzilla.redhat.com/show_bug.cgi?id=758366

https://bugzilla.redhat.com/show_bug.cgi?id=759375

https://bugzilla.redhat.com/show_bug.cgi?id=759377

https://bugzilla.redhat.com/show_bug.cgi?id=768377

https://bugzilla.redhat.com/show_bug.cgi?id=770357

https://bugzilla.redhat.com/show_bug.cgi?id=773242

https://bugzilla.redhat.com/show_bug.cgi?id=785163

https://bugzilla.redhat.com/show_bug.cgi?id=796176

https://bugzilla.redhat.com/show_bug.cgi?id=796216

https://bugzilla.redhat.com/show_bug.cgi?id=799027

https://bugzilla.redhat.com/show_bug.cgi?id=803618

https://bugzilla.redhat.com/show_bug.cgi?id=811147

https://bugzilla.redhat.com/show_bug.cgi?id=823411

Plugin Details

Severity: High

ID: 59589

File Name: redhat-RHSA-2012-0841.nasl

Version: 1.20

Type: local

Agent: unix

Published: 6/20/2012

Updated: 11/4/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2011-4088

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:btparser-devel, p-cpe:/a:redhat:enterprise_linux:libreport-plugin-kerneloops, p-cpe:/a:redhat:enterprise_linux:btparser, p-cpe:/a:redhat:enterprise_linux:libreport-devel, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:abrt-desktop, p-cpe:/a:redhat:enterprise_linux:libreport-python, p-cpe:/a:redhat:enterprise_linux:abrt-devel, p-cpe:/a:redhat:enterprise_linux:libreport-gtk-devel, p-cpe:/a:redhat:enterprise_linux:libreport-cli, p-cpe:/a:redhat:enterprise_linux:abrt-cli, p-cpe:/a:redhat:enterprise_linux:abrt-libs, p-cpe:/a:redhat:enterprise_linux:libreport-plugin-reportuploader, p-cpe:/a:redhat:enterprise_linux:abrt-addon-kerneloops, p-cpe:/a:redhat:enterprise_linux:abrt-gui, p-cpe:/a:redhat:enterprise_linux:libreport-plugin-rhtsupport, p-cpe:/a:redhat:enterprise_linux:python-meh, p-cpe:/a:redhat:enterprise_linux:abrt-addon-python, p-cpe:/a:redhat:enterprise_linux:btparser-python, p-cpe:/a:redhat:enterprise_linux:abrt-addon-vmcore, p-cpe:/a:redhat:enterprise_linux:abrt, p-cpe:/a:redhat:enterprise_linux:abrt-addon-ccpp, p-cpe:/a:redhat:enterprise_linux:libreport-plugin-mailx, p-cpe:/a:redhat:enterprise_linux:libreport-gtk, p-cpe:/a:redhat:enterprise_linux:abrt-tui, p-cpe:/a:redhat:enterprise_linux:libreport, p-cpe:/a:redhat:enterprise_linux:libreport-plugin-logger, p-cpe:/a:redhat:enterprise_linux:libreport-newt, p-cpe:/a:redhat:enterprise_linux:libreport-plugin-bugzilla

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 6/20/2012

Vulnerability Publication Date: 7/3/2012

Reference Information

CVE: CVE-2011-4088, CVE-2012-1106

RHSA: 2012:0841